CVE-2025-65229 Details
Description
A stored cross-site scripting (XSS) vulnerability exists in the web interface of Lyrion Music Server <= 9.0.3. An authenticated user with access to Settings Player can save arbitrary HTML/JavaScript in the Player name field. That value is stored by the server and later rendered without proper output encoding on the Information (Player Info) tab, causing the script to execute in the context of any user viewing that page.
A stored cross-site scripting vulnerability has been identified in the web interface of Lyrion Music Server versions through 9.0.3. This vulnerability allows an authenticated user with access to the Settings Player to inject arbitrary HTML or JavaScript into the Player name field. The injected content is saved by the server and later displayed on the Information (Player Info) tab without proper output encoding, enabling the script to execute in the context of any user viewing the page.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/iyadalkhatib98/My_CVES/tree/main/CVE-2025-65229 | [email protected] | |
| https://lyrion.org/ | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| lyrion lyrion music server | <= 9.0.3 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 20, 2026 | CVE Modified | [email protected] |
| Dec 11, 2025 | Initial Analysis | [email protected] |
| Dec 8, 2025 | CVE Modified | CISA-ADP |
| Dec 8, 2025 | New CVE Received | [email protected] |