PT-2018-12664 · Subsonic · Subsonic

Florian Nivette

·

Published

2018-09-21

·

Updated

2018-11-09

·

CVE-2018-14690

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Subsonic version 6.1.1
Description An issue was discovered that affects the general settings, specifically two stored cross-site scripting vulnerabilities in the title and subtitle parameters to the "generalSettings.view" endpoint. These vulnerabilities could be used to steal session information of a victim.
Recommendations For Subsonic version 6.1.1, avoid using the title and subtitle parameters in the generalSettings.view endpoint until the issue is resolved. As a temporary workaround, consider restricting access to the general settings page to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-14690

Affected Products

Subsonic