PT-2018-18958 · Subsonic · Subsonic Media Server

Florian Nivette

·

Publicado

2018-09-21

·

Atualizado

2018-11-09

·

CVE-2018-9282

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Subsonic Media Server version 6.1.1
Description A stored XSS issue was found in the podcast subscription form of the Subsonic Media Server. The add parameter to the podcastReceiverAdmin.view is vulnerable, allowing an attacker to inject a JavaScript payload without needing administrator access. This could lead to session manipulation or privilege elevation by targeting an administrative user.
Recommendations For Subsonic Media Server version 6.1.1, consider restricting access to the podcast subscription form until a fix is available. As a temporary workaround, avoid using the add parameter in the podcastReceiverAdmin.view to minimize the risk of exploitation.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-9282

Produtos afetados

Subsonic Media Server