Логотип exploitDog
bind:CVE-2025-67737
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-67737

Количество 2

Количество 2

nvd логотип

CVE-2025-67737

около 2 месяцев назад

AzuraCast is a self-hosted, all-in-one web radio management suite. Versions 0.23.1 mistakenly include an API endpoint that is intended for internal use by the SFTP software sftpgo, exposing it to the public-facing HTTP API for AzuraCast installations. A user with specific internal knowledge of a station's operations can craft a custom HTTP request that would affect the contents of a station's database, without revealing any internal information about the station. In order to carry out an attack, a malicious user would need to know a valid SFTP station username and the coordinating internal filesystem structure. This issue is fixed in version 0.23.2.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-9449-rphm-mjqr

около 2 месяцев назад

AzuraCast Vulnerable to Pre-Auth File Deletion & Admin RCE

CVSS3: 3.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-67737

AzuraCast is a self-hosted, all-in-one web radio management suite. Versions 0.23.1 mistakenly include an API endpoint that is intended for internal use by the SFTP software sftpgo, exposing it to the public-facing HTTP API for AzuraCast installations. A user with specific internal knowledge of a station's operations can craft a custom HTTP request that would affect the contents of a station's database, without revealing any internal information about the station. In order to carry out an attack, a malicious user would need to know a valid SFTP station username and the coordinating internal filesystem structure. This issue is fixed in version 0.23.2.

CVSS3: 3.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-9449-rphm-mjqr

AzuraCast Vulnerable to Pre-Auth File Deletion & Admin RCE

CVSS3: 3.1
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу