CVE-2024-41665 Vulnerability Details
/
/
/
CVE-2024-41665 Metadata Quick Info
CVE Published: 23/07/2024 |
CVE Updated: 02/08/2024 |
CVE Year: 2024
Source: GitHub_M |
Vendor: ampache |
Product: ampache
Status : PUBLISHED
CVE-2024-41665 Description
Ampache, a web based audio/video streaming application and file manager, has a stored cross-site scripting (XSS) vulnerability in versions prior to 6.6.0. This vulnerability exists in the "Playlists - Democratic - Configure Democratic Playlist" feature. An attacker with Content Manager permissions can set the Name field to `
`. When any administrator or user accesses the Democratic functionality, they will be affected by this stored XSS vulnerability. The attacker can exploit this vulnerability to obtain the cookies of any user or administrator who accesses the `democratic.php` file. Version 6.6.0 contains a patch for the issue.
Metrics
CVSS Version: 3.1 |
Base Score: 5.5 MEDIUM
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
l➤ Exploitability Metrics:
Attack Vector (AV)* NETWORK
Attack Complexity (AC)* LOW
Privileges Required (PR)* LOW
User Interaction (UI)* REQUIRED
Scope (S)* UNCHANGED
l➤ Impact Metrics:
Confidentiality Impact (C)* LOW
Integrity Impact (I)* LOW
Availability Impact (A)* LOW
Weakness Enumeration (CWE)
CWE-ID: CWE-79
CWE Name: CWE-79: Improper Neutralization of Input During Web Page Generation (
Cross-site Scripting
)
Source: ampache
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID:
CAPEC Description:
Source: NVD (National Vulnerability Database).