Reflected Cross-site Scripting Vulnerability in Music Store by CodePeople
CVE-2025-24626
7.1HIGH
Summary
The Music Store application by CodePeople is susceptible to a reflected Cross-site Scripting (XSS) vulnerability. This flaw arises due to improper neutralization of input during web page generation, which can allow an attacker to inject arbitrary scripts into web pages viewed by users. The vulnerability affects versions from n/a through 1.1.19, potentially compromising user data and leading to unauthorized actions on behalf of users. It is crucial for users to implement security measures and updates to safeguard against these types of attacks.
Affected Version(s)
Music Store <= 1.1.19
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
João Pedro S Alcântara (Kinorth) (Patchstack Alliance)