Описание
Ampache before version 4.2.2 allows unauthenticated users to perform SQL injection. Refer to the referenced GitHub Security Advisory for details and a workaround. This is fixed in version 4.2.2 and the development branch.
Ссылки
- PatchThird Party Advisory
- Release NotesThird Party Advisory
- ExploitMitigationThird Party Advisory
- PatchThird Party Advisory
- Release NotesThird Party Advisory
- ExploitMitigationThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.2.2 (исключая)
cpe:2.3:a:ampache:ampache:*:*:*:*:*:*:*:*
EPSS
Процентиль: 83%
0.02059
Низкий
8.2 High
CVSS3
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-89
Связанные уязвимости
CVSS3: 8.2
ubuntu
почти 5 лет назад
Ampache before version 4.2.2 allows unauthenticated users to perform SQL injection. Refer to the referenced GitHub Security Advisory for details and a workaround. This is fixed in version 4.2.2 and the development branch.
CVSS3: 8.2
debian
почти 5 лет назад
Ampache before version 4.2.2 allows unauthenticated users to perform S ...
EPSS
Процентиль: 83%
0.02059
Низкий
8.2 High
CVSS3
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-89