inMusic Brands Engine DJ before 4.3.4 suffers from Insecure Permissions due to exposed HTTP service in the Remote Library, which allows attackers to access all files and network paths.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66723.json"
[ { "events": [ { "introduced": "3.0.0" }, { "fixed": "4.3.4" } ] } ]