Impact
Lyrion Music Server 9.2.0 contains a path traversal vulnerability that allows attackers without authentication to read arbitrary files from the server by manipulating file path parameters in the web interface. This could expose sensitive configuration files, credentials, and other confidential data, leading to a compromise of confidentiality and potentially enabling further exploitation.
Affected Systems
The affected product is LMS Community’s Lyrion Music Server version 9.2.0.
Risk and Exploitability
This vulnerability scores 8.7 on the CVSS scale, categorizing it as high severity. No EPSS value is available and the issue is not listed in the KEV catalog. The attack vector is most likely over the network via the web server, and no authentication or special privileges are required to exploit the directory traversal. Thus, any remotely exposed instance of the 9.2.0 release is at high risk of unauthorized file disclosure.
OpenCVE Enrichment