Description
An issue was discovered in Ampache through 3.9.1. A stored XSS exists in the localplay.php LocalPlay "add instance" functionality. The injected code is reflected in the instances menu. This vulnerability can be abused to force an admin to create a new privileged user whose credentials are known by the attacker.
Remediation
References
Related Vulnerabilities
WordPress Plugin Image Slider by Ays-Responsive Slider and Carousel SQL Injection (2.4.9)
Moodle Insertion of Sensitive Information Into Sent Data Vulnerability (CVE-2025-67857)
OpenSSL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-3195)
WordPress Plugin Custom Contact Forms Security Bypass (5.1.0.3)
Oracle Database Server CVE-2023-22074 Vulnerability (CVE-2023-22074)