CVE-2024-51485
CVSS 3.1 Score 8.1 of 10 (high)
Details
Summary
CVE-2024-51485 is a vulnerability affecting Ampache, a web-based audio/video streaming application. The current implementation of token parsing in Ampache fails to validate CSRF tokens during plugin activation and deactivation, creating an opportunity for attackers to execute CSRF attacks. This could potentially allow unauthorized changes to website features, which should be managed only by administrators. The vulnerability has been addressed in version 7.0.1, and all users are advised to upgrade as soon as possible. At present, there are no known workarounds for this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Ampache
Affected Vendors
- Ampache