VDB

CVE-2021-32644

CVE-2021-32644 PUBLISHED

Ampache is an open source web based audio/video streaming application and file manager. Due to a lack of input filtering versions 4.x.y are vulnerable to code injection in random.php. The attack requires user authentication to access the random.php page unless the site is running in demo mode. This issue has been resolved in 4.4.3.

EPSS 0.44% · 63.6th percentile

Risk Scores

EPSS Score
0.44%
63.6th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSampache0, 3.6-rzb2779+dfsg-0ubuntu5, 3.6-rzb2779+dfsg-0ubuntu6

Timeline

  • Jun 22, 2021 CVE Published
  • Jun 23, 2021 EPSS Score
  • Aug 14, 2021 EPSS Score
  • Oct 22, 2021 EPSS Score
  • Dec 21, 2021 EPSS Score
  • Feb 20, 2022 EPSS Score
  • Apr 21, 2022 EPSS Score
  • Aug 21, 2022 EPSS Score
  • Oct 20, 2022 EPSS Score
  • Dec 19, 2022 EPSS Score
  • Feb 18, 2023 EPSS Score
  • Apr 19, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›