Vulnerability Database

296,747

Total vulnerabilities in the database

CVE-2024-28852

Ampache is a web based audio/video streaming application and file manager. Ampache has multiple reflective XSS vulnerabilities,this means that all forms in the Ampache that use rule as a variable are not secure. For example, when querying a song, when querying a podcast, we need to use $rule variable. This vulnerability is fixed in 6.3.1

  • Published: Mar 27, 2024
  • Updated: May 4, 2025
  • CVE: CVE-2024-28852
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 6.1
  • AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N