CVE-2025-66723

HIGH

inMusic Brands Engine DJ <4.3.4 - Info Disclosure

Title source: llm

Description

inMusic Brands Engine DJ before 4.3.4 suffers from Insecure Permissions due to exposed HTTP service in the Remote Library, which allows attackers to access all files and network paths.

Exploits (1)

nomisec WRITEUP
by audiopump · poc
https://github.com/audiopump/cve-2025-66723

Scores

CVSS v3 7.5
EPSS 0.0002
EPSS Percentile 6.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-732
Status published
Products (1)
inmusicbrands/engine_dj_desktop 3.0.0 - 4.3.4
Published Dec 30, 2025
Tracked Since Feb 18, 2026