Cross-site Scripting (XSS) - Reflected in GitHub repository ampache/ampache prior to 5.5.7.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://huntr.dev/bounties/0bfed46d-ac96-43c4-93fb-13f68b4e711b | third party advisory exploit |
https://github.com/ampache/ampache/commit/d3191503ca856dfe0b33d7cb17717ffd480046cb | third party advisory patch |