PT-2026-80981 · Azuracast+1 · Azuracast+1
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AzuraCast (affected versions not specified)
Description
An improper permission check in the profile editing process allows users with only profile permissions to modify Liquidsoap custom configuration fields. The endpoint 'PUT /api/station/{station id}/profile/edit' deserializes data using a general group that includes the
backend config property, bypassing the stricter permissions required by the dedicated configuration endpoint. This allows the modification of variables including custom config top, custom config, custom config pre playlists, custom config pre live, custom config pre fade, and custom config bottom. These values are written directly into the Liquidsoap .liq script, where the process.run() and process.exec() built-in functions can be used to execute operating system commands upon a backend restart.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Incorrect Authorization
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Azuracast
Liquidsoap