Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 07 Jun 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lyrion
Lyrion lyrion Music Server |
|
| Vendors & Products |
Lyrion
Lyrion lyrion Music Server |
Fri, 05 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 05 Jun 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Lyrion Music Server 9.2.0 contains an unauthenticated reflected cross-site scripting vulnerability in the server.log endpoint that allows attackers to inject arbitrary HTML and JavaScript code through the search parameter. Attackers can craft malicious URLs with JavaScript payloads in the search parameter to execute code in users' browsers within the context of the affected application. | |
| Title | Lyrion Music Server 9.2.0 Reflected XSS via server.log | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-05T19:27:07.601Z
Reserved: 2026-06-04T10:47:01.274Z
Link: CVE-2026-50230
Updated: 2026-06-05T19:27:03.268Z
Status : Deferred
Published: 2026-06-05T14:16:36.010
Modified: 2026-06-05T14:59:31.207
Link: CVE-2026-50230
No data.
OpenCVE Enrichment
Updated: 2026-06-07T11:16:56Z