Lyrion Music Server 9.2.0 contains an unauthenticated reflected cross-site scripting vulnerability in the server.log endpoint that allows attackers to inject arbitrary HTML and JavaScript code through the search parameter. Attackers can craft malicious URLs with JavaScript payloads in the search parameter to execute code in users' browsers within the context of the affected application.
Metrics
Affected Vendors & Products
References
History
Sun, 07 Jun 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lyrion
Lyrion lyrion Music Server |
|
| Vendors & Products |
Lyrion
Lyrion lyrion Music Server |
Fri, 05 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 05 Jun 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Lyrion Music Server 9.2.0 contains an unauthenticated reflected cross-site scripting vulnerability in the server.log endpoint that allows attackers to inject arbitrary HTML and JavaScript code through the search parameter. Attackers can craft malicious URLs with JavaScript payloads in the search parameter to execute code in users' browsers within the context of the affected application. | |
| Title | Lyrion Music Server 9.2.0 Reflected XSS via server.log | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-06-05T13:24:25.716Z
Updated: 2026-06-05T19:27:07.601Z
Reserved: 2026-06-04T10:47:01.274Z
Link: CVE-2026-50230
Updated: 2026-06-05T19:27:03.268Z
Status : Deferred
Published: 2026-06-05T14:16:36.010
Modified: 2026-06-05T14:59:31.207
Link: CVE-2026-50230
No data.