VDB

CVE-2020-15153

CVE-2020-15153 PUBLISHED CVSS 8.199999809265137 HIGH

Ampache before version 4.2.2 allows unauthenticated users to perform SQL injection. Refer to the referenced GitHub Security Advisory for details and a workaround. This is fixed in version 4.2.2 and the development branch.

EPSS 2.40% · 82.8th percentile

Risk Scores

CVSS 3.1
8.199999809265137
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
EPSS Score
2.40%
82.8th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSampache0, 3.6-rzb2779+dfsg-0ubuntu5, 3.6-rzb2779+dfsg-0ubuntu6

Timeline

  • Apr 30, 2021 CVE Published
  • May 1, 2021 EPSS Score
  • Jul 4, 2021 EPSS Score
  • Nov 6, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Jan 7, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 11, 2022 EPSS Score
  • Jul 13, 2022 EPSS Score
  • Sep 14, 2022 EPSS Score
  • Jan 16, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›