Description
Ampache is a web based audio/video streaming application and file manager. Stored Cross Site Scripting (XSS) vulnerability in ampache before v6.3.1 allows a remote attacker to execute code via a crafted payload to serval parameters in the post request of /preferences.php?action=admin_update_preferences. This vulnerability is fixed in 6.3.1.
Remediation
References
Related Vulnerabilities
Perl Improper Certificate Validation Vulnerability (CVE-2023-31486)
Apache HTTP Server Other Vulnerability (CVE-1999-0107)
WordPress Plugin WooCommerce Social Login PHP Object Injection (2.6.2)
WordPress Plugin FV Flowplayer Video Player SQL Injection (7.5.46.7212)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-1864)