PT-2026-45437 · Unknown · Lightweight Music Server
Zeroscience
·
Published
2026-06-01
·
Updated
2026-06-01
·
CVE-2026-48559
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Lightweight Music Server versions prior to 3.76.1
Description
A stored cross-site scripting issue exists where attackers can execute arbitrary JavaScript by embedding malicious HTML in media file metadata tags, specifically
GENRE, ARTIST, or ALBUM. The payload is saved during library scanning and executed automatically in the web interface because the tag content is rendered using the Wt::TextFormat::UnsafeXHTML format in the src/lms/ui/Utils.cpp file without proper sanitization.Recommendations
Update to a version later than 3.76.0.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lightweight Music Server