Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
XML external entity (XXE) vulnerability in the import playlist feature in Subsonic 6.1.1 might allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted XSPF playlist file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Subsonic 安全漏洞
Vulnerability Description
Subsonic是软件开发者Sindre Mehus开发和维护的一个媒体文件托管平台。 Subsonic 6.1.1版本中的导入播放列表功能存在XML外部实体注入漏洞。远程攻击者可借助特制的XSPF播放列表文件利用该漏洞实施服务器端请求伪造攻击。
CVSS Information
N/A
Vulnerability Type
N/A