Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g3v6-6vj7-mmpv

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary administrative actions via multiple crafted X-Plex-Url headers to system/proxy, which are inconsistently processed by the request handler in the backend web server.

Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary administrative actions via multiple crafted X-Plex-Url headers to system/proxy, which are inconsistently processed by the request handler in the backend web server.

EPSS

Процентиль: 84%
0.02201
Низкий

Связанные уязвимости

nvd
около 11 лет назад

Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary administrative actions via multiple crafted X-Plex-Url headers to system/proxy, which are inconsistently processed by the request handler in the backend web server.

EPSS

Процентиль: 84%
0.02201
Низкий