CVE-2025-66723
HIGHinMusic Brands Engine DJ <4.3.4 - Info Disclosure
Title source: llmDescription
inMusic Brands Engine DJ before 4.3.4 suffers from Insecure Permissions due to exposed HTTP service in the Remote Library, which allows attackers to access all files and network paths.
Exploits (1)
Scores
CVSS v3
7.5
EPSS
0.0002
EPSS Percentile
6.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-732
Status
published
Products (1)
inmusicbrands/engine_dj_desktop
3.0.0 - 4.3.4
Published
Dec 30, 2025
Tracked Since
Feb 18, 2026