CyberRota
← Ana sayfaya dön

CVE-2026-50233

MEDIUM · CVSS 5.3 EPSS %0.29

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-06-05T14:16:36.550 · Çekilme zamanı: 2026-06-30T12:11:27.607650+00:00

CyberRota Yorumu

Uzaktan istismar edilebilir olabilir.

CVE
CVE-2026-50233
Severity
MEDIUM
CVSS
5.3
EPSS
%0.29

Orijinal NVD Açıklaması

Lyrion Music Server 9.2.0 contains an arbitrary directory listing vulnerability in its readdirectory query, exposed through both the CLI service (TCP port 9090) and the HTTP JSON-RPC endpoint (/jsonrpc.js). The query accepts a folder parameter and lists its contents with no restriction to the configured media directories and no authentication in the default configuration, allowing a remote, unauthenticated attacker to enumerate arbitrary locations on the host filesystem.