Vulnerability Description
Ampache before version 4.2.2 allows unauthenticated users to perform SQL injection. Refer to the referenced GitHub Security Advisory for details and a workaround. This is fixed in version 4.2.2 and the development branch.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ampache | Ampache | < 4.2.2 |
Related Weaknesses (CWE)
References
- https://github.com/ampache/ampache/commit/e92cb6154c32c513b9c07e5fdbf5ac7de81ef5PatchThird Party Advisory
- https://github.com/ampache/ampache/releases/tag/4.2.2Release NotesThird Party Advisory
- https://github.com/ampache/ampache/security/advisories/GHSA-phr3-mpx5-7826ExploitMitigationThird Party Advisory
- https://github.com/ampache/ampache/commit/e92cb6154c32c513b9c07e5fdbf5ac7de81ef5PatchThird Party Advisory
- https://github.com/ampache/ampache/releases/tag/4.2.2Release NotesThird Party Advisory
- https://github.com/ampache/ampache/security/advisories/GHSA-phr3-mpx5-7826ExploitMitigationThird Party Advisory
FAQ
What is CVE-2020-15153?
CVE-2020-15153 is a vulnerability with a CVSS score of 8.2 (HIGH). Ampache before version 4.2.2 allows unauthenticated users to perform SQL injection. Refer to the referenced GitHub Security Advisory for details and a workaround. This is fixed in version 4.2.2 and th...
How severe is CVE-2020-15153?
CVE-2020-15153 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-15153?
Check the references section above for vendor advisories and patch information. Affected products include: Ampache Ampache.