PT-2024-34653 · Ampache · Ampache

Hacking-Notes

·

Published

2024-11-11

·

Updated

2024-11-14

·

CVE-2024-51489

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ampache versions prior to 7.0.1
Description The current implementation of token parsing in Ampache does not adequately validate CSRF tokens when users send messages to one another. This issue could be exploited to forge CSRF attacks, allowing an attacker to send messages to any user, including administrators, if they interact with a malicious request.
Recommendations For versions prior to 7.0.1, upgrade to version 7.0.1 to address the issue. As a temporary workaround, consider restricting user interactions with messages from unknown or untrusted sources to minimize the risk of exploitation.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-51489
GHSA-4Q69-983R-MWWR

Affected Products

Ampache