inMusic Brands Engine DJ before 4.3.4 suffers from Insecure Permissions due to exposed HTTP service in the Remote Library, which allows attackers to access all files and network paths.
References
| Link | Resource |
|---|---|
| https://github.com/audiopump/cve-2025-66723 | Exploit Third Party Advisory |
| https://www.inmusicbrands.com/ | Product |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2025-12-30 21:15
Updated : 2026-01-05 20:25
NVD link : CVE-2025-66723
Mitre link : CVE-2025-66723
CVE.ORG link : CVE-2025-66723
JSON object : View
Products Affected
microsoft
- windows
inmusicbrands
- engine_dj_desktop
apple
- macos
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
