Record summary

CVE-2026-50230 has a selected CVSS score of 5.1 (medium); EIP currently links 1 Nuclei template.

Description

Lyrion Music Server 9.2.0 contains an unauthenticated reflected cross-site scripting vulnerability in the server.log endpoint that allows attackers to inject arbitrary HTML and JavaScript code through the search parameter. Attackers can craft malicious URLs with JavaScript payloads in the search parameter to execute code in users' browsers within the context of the affected application.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 5, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List9.2.0affected

Nuclei templates

1
ProjectDiscoveryMEDIUMLyrion Music Server <= 9.2.0 - Cross-Site ScriptingCVSS 6.1

Lyrion Music Server 9.2.0 contains a reflected XSS caused by improper sanitization of the search parameter in the server.log endpoint, letting unauthenticated attackers execute arbitrary script in users' browsers.

Impact

Attackers can execute arbitrary JavaScript in users' browsers, potentially stealing session data or performing actions on behalf of users.

Remediation

Update to the latest version that patches this vulnerability.

WeaknessesCWE-79
Authors0x_Akoko
Template tagscvecve2026lyrionlmsxssreflectedunauth
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
FOFA: title="Lyrion Music Server"

Source: ProjectDiscovery

References

3