CVE-2013-7301: Craig Drummond Cantata
Medium severity, CVSS 5.0. EPSS: 1.5% chance of exploitation in the next 30 days.
Cantata before 1.2.2 does not restrict access to files in the play queue, which allows remote attackers to obtain sensitive information by reading the songs in the queue.
Affected products
- Craig Drummond Cantata: up to and including 1.2.1; version 0.7.0 only; version 0.7.1 only; version 0.8.0 only; version 0.8.1 only; version 0.8.2 only; …
Published 2014-02-02. Last modified 2026-06-17.