VDB
CVE-2021-32644
CVE-2021-32644
PUBLISHED
Ampache is an open source web based audio/video streaming application and file manager. Due to a lack of input filtering versions 4.x.y are vulnerable to code injection in random.php. The attack requires user authentication to access the random.php page unless the site is running in demo mode. This issue has been resolved in 4.4.3.
EPSS 0.44% · 63.6th percentile
Risk Scores
EPSS Score
0.44%
63.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:16.04:LTS | ampache | 0, 3.6-rzb2779+dfsg-0ubuntu5, 3.6-rzb2779+dfsg-0ubuntu6 |
Exploit Intelligence
- Ampache XSS (github-poc)
- Ampache XSS (github-poc)
- Ampache XSS (github-poc)
- Ampache XSS (github-poc)
- Ampache XSS (github-poc)
- https://github.com/ampache/ampache/security/advisories/GHSA-vqpj-xgw2-r54q (circl)
- https://github.com/ampache/ampache/commit/c9453841e1b517a1660c3da1efd1fe5d623c93a5 (circl)
Timeline
- Jun 22, 2021 CVE Published
- Jun 23, 2021 EPSS Score
- Aug 14, 2021 EPSS Score
- Oct 22, 2021 EPSS Score
- Dec 21, 2021 EPSS Score
- Feb 20, 2022 EPSS Score
- Apr 21, 2022 EPSS Score
- Aug 21, 2022 EPSS Score
- Oct 20, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 18, 2023 EPSS Score
- Apr 19, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2021-32644 third-party-advisory
- https://github.com/ampache/ampache/security/advisories/GHSA-vqpj-xgw2-r54q third-party-advisory
- https://github.com/ampache/ampache/commit/c9453841e1b517a1660c3da1efd1fe5d623c93a5 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2021-32644 third-party-advisory