Ampache Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2024-41665 - Vulnerability Database

Ampache Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2024-41665

Medium
Reference: CVE-2024-41665
Title: Ampache Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

Ampache a web based audio/video streaming application and file manager has a stored cross-site scripting (XSS) vulnerability in versions prior to 6.6.0. This vulnerability exists in the quotPlaylists - Democratic - Configure Democratic Playlistquot feature. An attacker with Content Manager permissions can set the Name field to ltsvg onloadalert(8)gt. When any administrator or user accesses the Democratic functionality they will be affected by this stored XSS vulnerability. The attacker can exploit this vulnerability to obtain the cookies of any user or administrator who accesses the democratic.php file. Version 6.6.0 contains a patch for the issue.