Cross-site Scripting (XSS) - Stored in ampache/ampache
Valid
Reported on
Aug 13th 2021
✍️ Description
This is a stored XSS in the mp3 management library.
🕵️♂️ Proof of Concept
- Edit meta data with Audacity:
- Create a new playlist that contains this file.
- Open "Artists" (1) under "Search" menu and then "Search" (2):
💥 Impact
By uploading an mp3 with javascript code into meta tag could permit an attacker to execute every type of javascript code in the browser of the user who imported that file, so steal cookies or execute other evil code.
Occurrences
We have contacted a member of the
ampache
team and are waiting to hear back
2 years ago
to join this conversation