5.1
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Description
Lyrion Music Server 9.2.0 contains a reflected cross-site scripting vulnerability in advanced search parameters that fail to properly sanitize user input before displaying it in search forms. Attackers can inject malicious scripts through unfiltered search parameters to execute arbitrary JavaScript in users' browsers and steal session information.
Basic Information
ID
CVE-2026-50235
Source
VulnCheck
Published
Jun 5, 2026 at 13:24
Modified
Jun 5, 2026 at 14:30
Affected Product
Vendor
LMS Community
Product
Lyrion Music Server
Version
9.2.0
Affected Versions
LMS Community Lyrion Music Server 9.2.0