Ampache是Ampache开源的一款基于Web的音频/视频应用程序和文件管理器。 Ampache 7.0.1版本存在跨站请求伪造漏洞,该漏洞源于当前令牌解析的实现在激活或停用目录时无法正确验证 CSRF 令牌。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-51490 | 5.5 MEDIUM | Stored Cross-Site Scripting in Ampache |
| CVE-2024-51486 | 5.5 MEDIUM | Stored Cross-Site Scripting in Ampache |
| CVE-2024-51489 | Insufficient Message Token Validation in Ampache | |
| CVE-2024-51488 | Insufficient Validation in Delete Message in Ampache | |
| CVE-2024-51484 | Insufficient Validation in Controllers (Activation/Deactivation) in Ampache | |
| CVE-2024-51485 | Insufficient Validation in Plugins (Activation/Deactivation) in Ampache |
No comments yet