Directory Traversal Vulnerabilities in Plex Media Server from Plex
CVE-2014-9181

Currently unrated

Key Information:

Vendor

Plex

Vendor
CVE Published:
2 December 2014

What is CVE-2014-9181?

Plex Media Server prior to version 0.9.9.3 is impacted by multiple directory traversal vulnerabilities. These flaws enable remote attackers to gain unintended access to sensitive files through manipulated URIs that utilize the '..' (dot dot) sequence. The vulnerabilities manifest in specific endpoints, allowing unauthorized reading of files under 'manage/' and 'web/' directories. Additionally, authenticated users can exploit the resources endpoint to access file content that should otherwise be restricted, leading to potential exposure of confidential information.

References

EPSS Score

9% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.