CVE-2024-28852: Ampache
Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.
Ampache is a web based audio/video streaming application and file manager. Ampache has multiple reflective XSS vulnerabilities,this means that all forms in the Ampache that use `rule` as a variable are not secure. For example, when querying a song, when querying a podcast, we need to use `$rule` variable. This vulnerability is fixed in 6.3.1
Affected products
- Ampache Ampache: before 6.3.1 (fixed in 6.3.1)
Published 2024-03-27. Last modified 2026-06-17.