VYPR

Phoniebox

by Sourcefabric

CVEs (8)

  • CVE-2024-41369CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.01

    RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWifi.php

  • CVE-2024-41368CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.01

    RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWlanIpMail.php

  • CVE-2024-41367CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.01

    RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\api\playlist\appendFileToPlaylist.php

  • CVE-2024-41366CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.01

    RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\userScripts.php

  • CVE-2024-41364CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.01

    RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\trackEdit.php

  • CVE-2024-41361CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.01

    RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\manageFilesFolders.php

  • CVE-2025-63951HigDec 18, 2025
    risk 0.49cvss 7.5epss 0.01

    An insecure deserialization vulnerability exists in the rss-mp3.php script of the MiczFlor RPi-Jukebox-RFID project through commit 4b2334f0ae0e87c0568876fc41c48c38aa9a7014 (2025-10-07). The 'rss' GET parameter receives data that is passed directly to the unserialize() function…

  • CVE-2024-0714MedJan 19, 2024
    risk 0.41cvss 6.3epss 0.02

    A vulnerability was found in MiczFlor RPi-Jukebox-RFID up to 2.5.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file userScripts.php of the component HTTP Request Handler. The manipulation of the argument folder with the input ;nc…