Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-367h-866v-prvm

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in Ampache through 3.9.1. A stored XSS exists in the localplay.php LocalPlay "add instance" functionality. The injected code is reflected in the instances menu. This vulnerability can be abused to force an admin to create a new privileged user whose credentials are known by the attacker.

An issue was discovered in Ampache through 3.9.1. A stored XSS exists in the localplay.php LocalPlay "add instance" functionality. The injected code is reflected in the instances menu. This vulnerability can be abused to force an admin to create a new privileged user whose credentials are known by the attacker.

EPSS

Процентиль: 48%
0.00251
Низкий

Связанные уязвимости

CVSS3: 5.4
ubuntu
больше 6 лет назад

An issue was discovered in Ampache through 3.9.1. A stored XSS exists in the localplay.php LocalPlay "add instance" functionality. The injected code is reflected in the instances menu. This vulnerability can be abused to force an admin to create a new privileged user whose credentials are known by the attacker.

CVSS3: 5.4
nvd
больше 6 лет назад

An issue was discovered in Ampache through 3.9.1. A stored XSS exists in the localplay.php LocalPlay "add instance" functionality. The injected code is reflected in the instances menu. This vulnerability can be abused to force an admin to create a new privileged user whose credentials are known by the attacker.

CVSS3: 5.4
debian
больше 6 лет назад

An issue was discovered in Ampache through 3.9.1. A stored XSS exists ...

EPSS

Процентиль: 48%
0.00251
Низкий