CVE-2024-51484

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Nov 11, 2024
Updated: Nov 14, 2024
CWE ID 352

Summary

CVE-2024-51484 is a vulnerability affecting Ampache, an open-source audio/video streaming application. The flaw lies in the token parsing process, which fails to adequately validate CSRF tokens during the activation or deactivation of controllers. An attacker can exploit this weakness to carry out CSRF attacks, potentially altering administrative website features unintendedly. Users are recommended to upgrade to version 7.0.1 to mitigate this risk, as no known workarounds are available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share