Ampache, a web based audio/video streaming application and file manager, has a stored cross-site scripting (XSS) vulnerability in versions prior to 6.6.0. This vulnerability exists in the "Playlists - Democratic - Configure Democratic Playlist" feature. An attacker with Content Manager permissions can set the Name field to `
- https://github.com/ampache/ampache/security/advisories/GHSA-cp44-89r2-fxph
No PoCs found on GitHub currently.