I’m using the latest version of volumio
When I access the web interface from a windows pc with Bitdefender Endpoint Security installed I get the following bitdefender message:
Your device is being used to conduct an attack attempt of type Exploit.CommandInjection.258. Please contact your system administrator.
In the console I get:
Failed to load resource: the server responded with a status of 403 (Bitdefender Endpoint Security Tools blocked this page)
The link it’s calling is:
http://192.168.0.70/{{::pluginComponent.pluginObj.host+’/albumart?sectionimage=%27+section.image}}
the full endpoint log is:
Detection details
THREAT INFO
Threat type:
Lateral movement
URL:
[HTTP://192.168.0.7/%7B%7B::pluginComponent.pluginObj.host+'/albumart?sectionimage='+section.image}](http://192.168.0.7/%7B%7B::pluginComponent.pluginObj.host+'/albumart?sectionimage=%27+section.image%7d)}
AFFECTED ENDPOINT
Endpoint name:
DESKTOP-678678678678678678
Endpoint type:
Workstation
IP: