Description
A Stored Cross Site Scripting (XSS) vulnerability was found in "/music/ajax.php?action=save_playlist" in Kashipara Music Management System v1.0. This vulnerability allows remote attackers to execute arbitrary code via "title" & "description" parameter fields.
In plain language
AI Worth attentionKashipara Music Management System v1.0 has a flaw that can let a malicious playlist affect people who open it, so businesses using it should address it.
Stored XSS in Kashipara Music Management System’s playlist-save endpoint allows attacker-supplied title or description content to execute in another user’s browser when rendered.
What to do now
- Check whether you run Kashipara Music Management System and whether users can create or view shared playlists.
- Restrict access to playlist creation and viewing to trusted, authenticated users until the issue is resolved.
- Ask the vendor for an update: no fixed version has been published.
- Review playlists for unexpected titles or descriptions and remove suspicious entries.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:CScopeC:LConfidentialityI:LIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2024-42787 and every CVE in our database. Create a free account — no credit card required.
Create Free Account