Musicco 2.0.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary directories by manipulating the parent parameter. Attackers can supply directory traversal sequences in the parent parameter of the getAlbum endpoint to access sensitive system directories and download them as ZIP files.
Metrics
Affected Vendors & Products
References
History
Fri, 06 Mar 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Musicco 2.0.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary directories by manipulating the parent parameter. Attackers can supply directory traversal sequences in the parent parameter of the getAlbum endpoint to access sensitive system directories and download them as ZIP files. | |
| Title | Musicco 2.0.0 Arbitrary Directory Download via Path Traversal | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-06T12:19:10.571Z
Reserved: 2026-03-06T11:49:35.798Z
Link: CVE-2018-25181
No data.
Status : Received
Published: 2026-03-06T13:16:00.447
Modified: 2026-03-06T13:16:00.447
Link: CVE-2018-25181
No data.
OpenCVE Enrichment
No data.