Reflected Cross-site Scripting Vulnerability in Music Store by CodePeople
CVE-2025-24626
What is CVE-2025-24626?
The Music Store application by CodePeople is susceptible to a reflected Cross-site Scripting (XSS) vulnerability. This flaw arises due to improper neutralization of input during web page generation, which can allow an attacker to inject arbitrary scripts into web pages viewed by users. The vulnerability affects versions from n/a through 1.1.19, potentially compromising user data and leading to unauthorized actions on behalf of users. It is crucial for users to implement security measures and updates to safeguard against these types of attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Music Store <= 1.1.19
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved