CVE-2024-47828

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Oct 9, 2024
CWE ID 352

Summary

CVE-2024-47828 is a vulnerability affecting the Ampache web-based audio/video streaming application, which can be exploited through a Cross-Site Request Forgery (CSRF) attack. This flaw allows unauthorized deletion of user playlists and similar objects if an authenticated user is tricked into executing a malicious script with another user's playlist ID. The exploitation requires user interaction, putting any active session at risk without needing special privileges. Organizations using affected products should implement preventive measures against CSRF attacks, such as validating requests and using anti-CSRF tokens. The potential impact includes significant integrity loss of user data, categorized with a medium severity score of 5.3 and a high integrity impact rating.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share