CVE-2024-51485

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Nov 11, 2024
Updated: Nov 14, 2024
CWE ID 352

Summary

CVE-2024-51485 is a vulnerability affecting Ampache, a web-based audio/video streaming application. The current implementation of token parsing in Ampache fails to validate CSRF tokens during plugin activation and deactivation, creating an opportunity for attackers to execute CSRF attacks. This could potentially allow unauthorized changes to website features, which should be managed only by administrators. The vulnerability has been addressed in version 7.0.1, and all users are advised to upgrade as soon as possible. At present, there are no known workarounds for this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share