Access Control Vulnerability in Tautulli Product by Plex
CVE-2018-21031
6.5MEDIUM
Key Information:
- Vendor
Plex
- Status
- Vendor
- CVE Published:
- 18 November 2019
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2018-21031?
A security flaw in Tautulli allows remote attackers to bypass access controls in Plex Media Server due to improper handling of the X-Plex-Token. This vulnerability permits unauthorized access to potentially sensitive server information, exposing users to significant risks.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
