Directory Traversal Vulnerabilities in Plex Media Server from Plex
CVE-2014-9181
Currently unrated
What is CVE-2014-9181?
Plex Media Server prior to version 0.9.9.3 is impacted by multiple directory traversal vulnerabilities. These flaws enable remote attackers to gain unintended access to sensitive files through manipulated URIs that utilize the '..' (dot dot) sequence. The vulnerabilities manifest in specific endpoints, allowing unauthorized reading of files under 'manage/' and 'web/' directories. Additionally, authenticated users can exploit the resources endpoint to access file content that should otherwise be restricted, leading to potential exposure of confidential information.
