VYPR
High severity8.2NVD Advisory· Published Apr 30, 2021· Updated Jun 17, 2026

CVE-2020-15153

CVE-2020-15153

Description

Ampache before version 4.2.2 allows unauthenticated users to perform SQL injection. Refer to the referenced GitHub Security Advisory for details and a workaround. This is fixed in version 4.2.2 and the development branch.

Affected products

3
  • Ampache/Ampache3 versions
    cpe:2.3:a:ampache:ampache:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:ampache:ampache:*:*:*:*:*:*:*:*range: <4.2.2
    • (no CPE)range: <4.2.2
    • (no CPE)range: < 4.2.2

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.