Sourcefabric
Sourcefabric Phoniebox: vulnerabilidades y CVE
Sourcefabric Phoniebox tiene 10 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 7 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses1
Críticas7
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-63951 | Alta (7.5) | 0.53% | — | 18 dic 2025 | An insecure deserialization vulnerability exists in the rss-mp3.php script of the MiczFlor RPi-Jukebox-RFID project through commit 4b2334f0ae0e87c0568876fc41c48c38aa9a7014 (2025-10-07). The 'rss' GET parameter receives… |
| CVE-2024-41369 | Crítica (9.8) | 0.95% | — | 29 ago 2024 | RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWifi.php |
| CVE-2024-41368 | Crítica (9.8) | 0.95% | — | 29 ago 2024 | RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWlanIpMail.php |
| CVE-2024-41367 | Crítica (9.8) | 0.95% | — | 29 ago 2024 | RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\api\playlist\appendFileToPlaylist.php |
| CVE-2024-41366 | Crítica (9.8) | 0.95% | — | 29 ago 2024 | RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\userScripts.php |
| CVE-2024-41364 | Crítica (9.8) | 0.95% | — | 29 ago 2024 | RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\trackEdit.php |
| CVE-2024-41361 | Crítica (9.8) | 0.95% | — | 29 ago 2024 | RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\manageFilesFolders.php |
| CVE-2024-3799 | Alta (8.7) | 15% | — | 10 jul 2024 | Insecure handling of POST header parameter body included in requests being sent to an instance of the open-source project Phoniebox allows an attacker to create a website, which – when visited by a user – will send… |
| CVE-2024-3798 | Alta (8.7) | 0.48% | — | 10 jul 2024 | Insecure handling of GET header parameter file included in requests being sent to an instance of the open-source project Phoniebox allows an attacker to create a website, which – when visited by a user – will send… |
| CVE-2024-0714 | Crítica (9.8) | 1.6% | — | 19 ene 2024 | A vulnerability was found in MiczFlor RPi-Jukebox-RFID up to 2.5.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file userScripts.php of the component HTTP Request Handler.… |