Описание
Navidrome is an open source web-based music collection server and streamer. Versions 0.55.0 through 0.55.2 have a vulnerability due to improper input validation on the role parameter within the API endpoint /api/artist. Attackers can exploit this flaw to inject arbitrary SQL queries, potentially gaining unauthorized access to the backend database and compromising sensitive user information. Version 0.56.0 contains a patch for the issue.
Уязвимые конфигурации
Конфигурация 1Версия от 0.55.0 (включая) до 0.56.0 (исключая)
cpe:2.3:a:navidrome:navidrome:*:*:*:*:*:*:*:*
EPSS
Процентиль: 24%
0.00081
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-89
Связанные уязвимости
EPSS
Процентиль: 24%
0.00081
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-89