PT-2024-29494 · Ampache · Ampache

Hebing123

·

Published

2024-07-23

·

Updated

2024-07-24

·

CVE-2024-41665

CVSS v3.1

5.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Ampache versions prior to 6.6.0
Description The issue is a stored cross-site scripting (XSS) vulnerability in the "Playlists - Democratic - Configure Democratic Playlist" feature. An attacker with Content Manager permissions can exploit this by setting the Name field to malicious code, such as <svg onload=alert(8)>, which will affect administrators or users accessing the Democratic functionality. This can lead to the attacker obtaining cookies of affected users. The vulnerability is exploited through the democratic.php file.
Recommendations For versions prior to 6.6.0, update to version 6.6.0 to resolve the issue.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-41665
GHSA-CP44-89R2-FXPH

Affected Products

Ampache