Azuracast

Azuracast

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.23%
  • Veröffentlicht 17.08.2026 00:00:00
  • Zuletzt bearbeitet 18.08.2026 16:18:14

zuraCast versions up to and including 0.23.7 contain a SQL injection vulnerability in the backup restore functionality. The `azuracast:restore` command executes the `db.sql` file extracted from a backup archive without any content validation or sanit...

Exploit
  • EPSS 0.83%
  • Veröffentlicht 09.05.2026 19:44:05
  • Zuletzt bearbeitet 24.07.2026 19:10:00

AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the currentDirectory request parameter in the Flow.js media upload endpoint (POST /api/station/{station_id}/files/upload) is not sanitized for path traversal ...

Exploit
  • EPSS 0.48%
  • Veröffentlicht 09.05.2026 19:43:35
  • Zuletzt bearbeitet 24.07.2026 19:10:00

AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the ApplyXForwarded middleware unconditionally trusts the client-supplied X-Forwarded-Host HTTP header with no trusted proxy allowlist. An unauthenticated att...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 12.12.2025 06:53:15
  • Zuletzt bearbeitet 17.02.2026 14:52:29

AzuraCast is a self-hosted, all-in-one web radio management suite. Versions 0.23.1 mistakenly include an API endpoint that is intended for internal use by the SFTP software sftpgo, exposing it to the public-facing HTTP API for AzuraCast installations...

Exploit
  • EPSS 0.79%
  • Veröffentlicht 05.05.2023 01:15:08
  • Zuletzt bearbeitet 21.11.2024 07:58:47

Improper Restriction of Excessive Authentication Attempts in GitHub repository azuracast/azuracast prior to 0.18.3.

Exploit
  • EPSS 0.5%
  • Veröffentlicht 20.04.2023 02:15:06
  • Zuletzt bearbeitet 21.11.2024 07:58:06

Cross-site Scripting (XSS) - Stored in GitHub repository azuracast/azuracast prior to 0.18.