CVE 5.1 MEDIUM

Lightweight Music Server 3.76.0 Stored XSS via Media File Metadata Tags_CVE-2026-48559

5.1 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Description

Lightweight Music Server (LMS) though 3.76.0 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by embedding malicious HTML in media file metadata tags such as GENRE, ARTIST, or ALBUM. Attackers can introduce a crafted media file into the victim's library, causing the payload to be saved during library scanning and executed automatically in the web interface due to tag content being rendered using Wt::TextFormat::UnsafeXHTML without sanitization in src/lms/ui/Utils.cpp.

Basic Information

ID CVE-2026-48559
Source VulnCheck
Published Jun 1, 2026 at 13:15
Modified Jun 1, 2026 at 14:23

Affected Product

Vendor epoupon
Product lms
Affected Versions epoupon lms 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.