PT-2026-3505 · Unknown · Swingmusic
D-Virtuosa
·
Publicado
2026-01-19
·
Atualizado
2026-03-13
·
CVE-2026-23877
CVSS v4.0
5.3
Média
| Vetor | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Swing Music versions prior to 2.1.4
Description
Swing Music is a self-hosted music player for local audio files. The
list folders() function within the /folder/dir-browser API endpoint is susceptible to directory traversal attacks. Authenticated users, even those without administrative privileges, can potentially browse arbitrary directories on the server filesystem.Recommendations
Update to version 2.1.4 or later.
Exploit
Correção
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Swingmusic