CVE-2021-32644
Last modified
CVE-2021-32644 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Ampache is an open source web based audio/video streaming application and file manager. Due to a lack of input filtering versions 4.x.y are vulnerable to code injection in random.php. EPSS estimates a 0.84% chance of exploitation in the next 30 days.
Description
Ampache is an open source web based audio/video streaming application and file manager. Due to a lack of input filtering versions 4.x.y are vulnerable to code injection in random.php. The attack requires user authentication to access the random.php page unless the site is running in demo mode. This issue has been resolved in 4.4.3.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ampache | Ampache | 4.4.2 |
References
- https://github.com/ampache/ampache/commit/c9453841e1b517a1660c3da1efd1fe5d623c93a5Patch, Third Party Advisory
- https://github.com/ampache/ampache/security/advisories/GHSA-vqpj-xgw2-r54qThird Party Advisory
- https://github.com/ampache/ampache/commit/c9453841e1b517a1660c3da1efd1fe5d623c93a5Patch, Third Party Advisory
- https://github.com/ampache/ampache/security/advisories/GHSA-vqpj-xgw2-r54qThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-32644?
How severe is CVE-2021-32644?
How do I fix CVE-2021-32644?
Are you affected by CVE-2021-32644?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
