PT-2018-18958 · Subsonic · Subsonic Media Server
Florian Nivette
·
Publicado
2018-09-21
·
Atualizado
2018-11-09
·
CVE-2018-9282
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Subsonic Media Server version 6.1.1
Description
A stored XSS issue was found in the podcast subscription form of the Subsonic Media Server. The
add parameter to the podcastReceiverAdmin.view is vulnerable, allowing an attacker to inject a JavaScript payload without needing administrator access. This could lead to session manipulation or privilege elevation by targeting an administrative user.Recommendations
For Subsonic Media Server version 6.1.1, consider restricting access to the podcast subscription form until a fix is available. As a temporary workaround, avoid using the
add parameter in the podcastReceiverAdmin.view to minimize the risk of exploitation.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Subsonic Media Server