Remote Code Execution Vulnerability in Plex Media Server by Plex
CVE-2019-19141
8.8HIGH
What is CVE-2019-19141?
The Camera Upload feature in Plex Media Server version 1.18.2.2029 is prone to a vulnerability that allows remote authenticated users to write files in unauthorized locations. By exploiting this flaw, attackers can perform directory traversal, potentially creating a .ssh directory in the home folder of the Plex user on systems like Ubuntu. This manipulation can lead to uploading an SSH authorized_keys file, granting attackers unauthorized access to the server via SSH, thereby compromising system integrity and security.
