Impact
Lyrion Music Server 9.2.0 contains an unauthenticated stored cross‑site scripting flaw in its log viewer component. The defect arises from unescaped template variables, allowing an attacker to embed malicious JavaScript via search, lines, path query parameters or by causing values such as URLs, User‑Agent headers, stream titles, or player names to be logged. When a victim’s browser renders the log entry, the injected script executes in that context.
Affected Systems
The affected product is Lyrion Music Server Community, version 9.2.0. No other versions are listed as impacted.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. Because the exploit does not require authentication and the log viewer is publicly reachable, the risk is non‑negligible. With no EPSS score available and the vulnerability not listed in CISA KEV, the current exploitation likelihood is unknown, but an attacker can trigger the flaw by sending a crafted request that logs malicious payloads and then causing an administrator or other authenticated user to view the log, at which point the injected script runs in their browser.
OpenCVE Enrichment