VDB

CVE-2021-32644

CVE-2021-32644 PUBLISHED CVSS 6.400000095367432 MEDIUM

Ampache is an open source web based audio/video streaming application and file manager. Due to a lack of input filtering versions 4.x.y are vulnerable to code injection in random.php. The attack requires user authentication to access the random.php page unless the site is running in demo mode. This issue has been resolved in 4.4.3.

EPSS 0.84% · 56.5th percentile

Risk Scores

CVSS 3.1
6.400000095367432
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
EPSS Score
0.84%
56.5th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSampache0, 3.6-rzb2779+dfsg-0ubuntu5, 3.6-rzb2779+dfsg-0ubuntu6

Timeline

  • Jun 22, 2021 CVE Published
  • Jun 23, 2021 EPSS Score
  • Aug 14, 2021 EPSS Score
  • Oct 23, 2021 EPSS Score
  • Dec 23, 2021 EPSS Score
  • Feb 22, 2022 EPSS Score
  • Apr 24, 2022 EPSS Score
  • Aug 25, 2022 EPSS Score
  • Oct 25, 2022 EPSS Score
  • Dec 25, 2022 EPSS Score
  • Feb 24, 2023 EPSS Score
  • Apr 26, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›