PT-2021-3394 · Ampache · Ampache

Ali Oguz

·

Published

2021-06-22

·

Updated

2021-08-15

·

CVE-2021-32644

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ampache versions 4.x.y through 4.4.2
Description The issue is related to a lack of protection for the web page structure, which can be exploited for cross-site scripting attacks. Additionally, there is a code injection vulnerability in the random.php file due to insufficient input filtering. The exploitation of this issue may require user authentication to access the vulnerable page, unless the site is in demo mode.
Recommendations For Ampache versions 4.x.y through 4.4.2, update to version 4.4.3 to resolve the issue. As a temporary workaround, consider restricting access to the random.php page to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03245
CVE-2021-32644
GHSA-VQPJ-XGW2-R54Q

Affected Products

Ampache