Description
An issue was discovered in Ampache through 3.9.1. A stored XSS exists in the localplay.php LocalPlay "add instance" functionality. The injected code is reflected in the instances menu. This vulnerability can be abused to force an admin to create a new privileged user whose credentials are known by the attacker.
Remediation
References
Related Vulnerabilities
PHP Numeric Errors Vulnerability (CVE-2011-1471)
Apache Tomcat Exposure of Resource to Wrong Sphere Vulnerability (CVE-2017-5648)
WordPress 3.0.4 Multiple Vulnerabilities (0.6.2 - 3.0.4)
WordPress Plugin GigPress Multiple Vulnerabilities (2.3.10)
Oracle Database Server CVE-2019-2734 Vulnerability (CVE-2019-2734)