PT-2024-34648 · Ampache · Ampache
Hacking-Notes
·
Published
2024-11-11
·
Updated
2024-11-14
·
CVE-2024-51484
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ampache versions prior to 7.0.1
Description
The issue concerns the improper validation of CSRF tokens in the token parsing implementation, allowing attackers to exploit CSRF attacks. This could enable them to change website features that should only be managed by administrators through malicious requests.
Recommendations
For versions prior to 7.0.1, upgrade to version 7.0.1 to address the issue. As a temporary workaround, consider restricting access to controller activation and deactivation features to minimize the risk of exploitation. Avoid using the application's administrative features from untrusted networks until the issue is resolved.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ampache