CVE-2021-32644

MEDIUM LAB

Ampache - XSS

Title source: rule
STIX 2.1

Description

Ampache is an open source web based audio/video streaming application and file manager. Due to a lack of input filtering versions 4.x.y are vulnerable to code injection in random.php. The attack requires user authentication to access the random.php page unless the site is running in demo mode. This issue has been resolved in 4.4.3.

Exploits (1)

nomisec WORKING POC
by dnr6419 · poc
https://github.com/dnr6419/CVE-2021-32644

References (2)

Core 2
Core References

Scores

CVSS v3 6.4
EPSS 0.0044
EPSS Percentile 63.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

Lab Environment

COMMUNITY
Community Lab
docker pull ampache/ampache:4.4.2

Details

CWE
CWE-79
Status published
Products (1)
ampache/ampache 4.4.2
Published Jun 22, 2021
Tracked Since Feb 18, 2026