PT-2025-49593 · Unknown · Lyrion Music Server

Publicado

2025-12-08

·

Atualizado

2025-12-16

·

CVE-2025-65229

CVSS v3.1

4.6

Média

VetorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Lyrion Music Server versions prior to 9.0.4
Description A stored cross-site scripting (XSS) issue exists in the web interface. An authenticated user with access to Settings Player can save arbitrary HTML/JavaScript in the Player name field. This value is stored and later rendered without proper output encoding on the Information (Player Info) tab, leading to script execution in the context of any user viewing that page.
Recommendations Update Lyrion Music Server to a version prior to 9.0.4.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-65229

Produtos afetados

Lyrion Music Server