漏洞标题
Ampache中Controllers(激活/失效)验证不足漏洞
漏洞描述信息
Ampache 是一款基于Web的音频/视频流应用和文件管理器。当前的令牌解析实现未能在激活或停用控制器时正确验证CSRF令牌。该漏洞允许攻击者利用CSRF攻击,可能使他们通过恶意请求更改应仅由管理员管理的网站功能。此问题已在版本7.0.1中得到修复,建议所有用户进行升级。目前尚无针对此漏洞的解决方法。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
漏洞类别
跨站请求伪造(CSRF)
漏洞标题
Insufficient Validation in Controllers (Activation/Deactivation) in Ampache
漏洞描述信息
Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSRF tokens when activating or deactivating controllers. This vulnerability allows an attacker to exploit CSRF attacks, potentially enabling them to change website features that should only be managed by administrators through malicious requests. This issue has been addressed in version 7.0.1 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
CVSS信息
N/A
漏洞类别
跨站请求伪造(CSRF)
漏洞标题
Ampache 跨站请求伪造漏洞
漏洞描述信息
Ampache是Ampache开源的一款基于Web的音频/视频应用程序和文件管理器。 Ampache 7.0.1版本存在跨站请求伪造漏洞,该漏洞源于当前令牌解析的实现在激活或停用控制器时无法正确验证 CSRF 令牌。
CVSS信息
N/A
漏洞类别
跨站请求伪造