PT-2024-34648 · Ampache · Ampache

Hacking-Notes

·

Published

2024-11-11

·

Updated

2024-11-14

·

CVE-2024-51484

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ampache versions prior to 7.0.1
Description The issue concerns the improper validation of CSRF tokens in the token parsing implementation, allowing attackers to exploit CSRF attacks. This could enable them to change website features that should only be managed by administrators through malicious requests.
Recommendations For versions prior to 7.0.1, upgrade to version 7.0.1 to address the issue. As a temporary workaround, consider restricting access to controller activation and deactivation features to minimize the risk of exploitation. Avoid using the application's administrative features from untrusted networks until the issue is resolved.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-51484
GHSA-H6VJ-6RVC-3X29

Affected Products

Ampache