Ampache before version 4.2.2 allows unauthenticated users to perform SQL injection. Refer to the referenced GitHub Security Advisory for details and a workaround. This is fixed in version 4.2.2 and the development branch.
References
Link | Resource |
---|---|
https://github.com/ampache/ampache/releases/tag/4.2.2 | Release Notes Third Party Advisory |
https://github.com/ampache/ampache/commit/e92cb6154c32c513b9c07e5fdbf5ac7de81ef5ed | Patch Third Party Advisory |
https://github.com/ampache/ampache/security/advisories/GHSA-phr3-mpx5-7826 | Exploit Mitigation Third Party Advisory |
Configurations
Information
Published : 2021-04-30 09:15
Updated : 2021-05-08 19:29
NVD link : CVE-2020-15153
Mitre link : CVE-2020-15153
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
ampache
- ampache