PT-2026-3505 · Unknown · Swingmusic

D-Virtuosa

·

Publicado

2026-01-19

·

Atualizado

2026-03-13

·

CVE-2026-23877

CVSS v4.0

5.3

Média

VetorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Swing Music versions prior to 2.1.4
Description Swing Music is a self-hosted music player for local audio files. The list folders() function within the /folder/dir-browser API endpoint is susceptible to directory traversal attacks. Authenticated users, even those without administrative privileges, can potentially browse arbitrary directories on the server filesystem.
Recommendations Update to version 2.1.4 or later.

Exploit

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-23877
GHSA-PJ88-9XWW-GXMH

Produtos afetados

Swingmusic