📦 Airsonic

by Airsonic Project

🔍 What is Airsonic?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2019-10907

CRITICAL CVSS 9.8 Apr 7, 2019

Airsonic 10.2.1 uses Spring's default remember-me authentication with a fixed MD5 key, allowing attackers who capture authentication cookies to offline brute-force user passwords. This affects all Air...

CVE-2018-20222

CRITICAL CVSS 9.8 Apr 4, 2019

CVE-2018-20222 is an XML External Entity (XXE) vulnerability in Airsonic that allows attackers to read arbitrary files from the server filesystem and potentially perform server-side request forgery. T...