7.5
CVSSv2

CVE-2014-9304

Published: 07/12/2014 Updated: 10/12/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Plex Media Server prior to 0.9.9.3 allows remote malicious users to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary administrative actions via multiple crafted X-Plex-Url headers to system/proxy, which are inconsistently processed by the request handler in the backend web server.

Vulnerable Product Search on Vulmon Subscribe to Product

plex media server

Exploits

SEC Consult Vulnerability Lab Security Advisory < 20140228-1 > ======================================================================= title: Authentication bypass (SSRF) and local file disclosure product: Plex Media Server vulnerable version: <=0992374-aa23a69 fixed version: >=0993 impact: Critical homepage: wwwplextv f ...