Ampache before version 4.2.2 allows unauthenticated users to perform SQL injection. Refer to the referenced GitHub Security Advisory for details and a workaround. This is fixed in version 4.2.2 and the development branch.
{ "binaries": [ { "binary_version": "3.6-rzb2779+dfsg-0ubuntu9.2", "binary_name": "ampache" }, { "binary_version": "3.6-rzb2779+dfsg-0ubuntu9.2", "binary_name": "ampache-common" } ] }