No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 09 Mar 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Musicco
Musicco musicco |
|
| Vendors & Products |
Musicco
Musicco musicco |
Fri, 06 Mar 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Musicco 2.0.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary directories by manipulating the parent parameter. Attackers can supply directory traversal sequences in the parent parameter of the getAlbum endpoint to access sensitive system directories and download them as ZIP files. | |
| Title | Musicco 2.0.0 Arbitrary Directory Download via Path Traversal | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-09T19:03:08.158Z
Reserved: 2026-03-06T11:49:35.798Z
Link: CVE-2018-25181
Updated: 2026-03-09T19:03:03.429Z
Status : Awaiting Analysis
Published: 2026-03-06T13:16:00.447
Modified: 2026-03-09T13:35:34.633
Link: CVE-2018-25181
No data.
OpenCVE Enrichment
Updated: 2026-03-09T10:07:47Z