Search CVE reports
1 – 10 of 25 results
CVE-2024-51490
Medium priorityAmpache is a web based audio/video streaming application and file manager. This vulnerability exists in the interface section of the Ampache menu, where users can change "Custom URL - Logo". This section is not properly sanitized,...
1 affected package
ampache
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ampache | Not in release | Not in release | Not in release | — | Needs evaluation |
CVE-2024-51489
Medium priorityAmpache is a web based audio/video streaming application and file manager. The current implementation of token parsing does not adequately validate CSRF tokens when users send messages to one another. This vulnerability could be...
1 affected package
ampache
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ampache | Not in release | Not in release | Not in release | — | Needs evaluation |
CVE-2024-51488
Medium priorityAmpache is a web based audio/video streaming application and file manager. The current implementation of token parsing does not adequately validate CSRF tokens when users delete messages. This vulnerability could be exploited to...
1 affected package
ampache
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ampache | Not in release | Not in release | Not in release | — | Needs evaluation |
CVE-2024-51487
Medium priorityAmpache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSRF tokens when activating or deactivating catalog. This vulnerability allows an...
1 affected package
ampache
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ampache | Not in release | Not in release | Not in release | — | Needs evaluation |
CVE-2024-51486
Medium priorityAmpache is a web based audio/video streaming application and file manager. The vulnerability exists in the interface section of the Ampache menu, where users can change the "Custom URL?-?Favicon". This section is not properly...
1 affected package
ampache
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ampache | Not in release | Not in release | Not in release | — | Needs evaluation |
CVE-2024-51485
Medium priorityAmpache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSRF tokens when activating or deactivating plugins. This vulnerability allows an...
1 affected package
ampache
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ampache | Not in release | Not in release | Not in release | — | Needs evaluation |
CVE-2024-51484
Medium priorityAmpache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSRF tokens when activating or deactivating controllers. This vulnerability allows...
1 affected package
ampache
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ampache | Not in release | Not in release | Not in release | — | Needs evaluation |
CVE-2024-47828
Medium priorityampache is a web based audio/video streaming application and file manager. A CSRF attack can be performed in order to delete objects (Playlist, smartlist etc.). Cross-Site Request Forgery (CSRF) is an attack that...
1 affected package
ampache
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ampache | Not in release | Not in release | Not in release | — | Needs evaluation |
CVE-2024-47184
Medium priorityAmpache is a web based audio/video streaming application and file manager. Prior to version 6.6.0, the Democratic Playlist Name is vulnerable to a stored cross-site scripting. Version 6.6.0 fixes this issue.
1 affected package
ampache
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ampache | Not in release | Not in release | Not in release | — | Needs evaluation |
CVE-2024-41665
Medium priorityAmpache, a web based audio/video streaming application and file manager, has a stored cross-site scripting (XSS) vulnerability in versions prior to 6.6.0. This vulnerability exists in the "Playlists - Democratic -...
1 affected package
ampache
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ampache | Not in release | Not in release | Not in release | — | Needs evaluation |