Cross Site Scripting Vulnerability in Emby Server by MediaBrowser
CVE-2021-25828
6.1MEDIUM
What is CVE-2021-25828?
Emby Server versions earlier than 4.6.0.50 are susceptible to a Cross Site Scripting (XSS) vulnerability. This security flaw allows an attacker to execute arbitrary JavaScript commands through a specially crafted GET request directed at the /web endpoint. Potential exploitation can lead to unauthorized actions on behalf of users and the exposure of sensitive information. It is crucial for users operating affected versions to apply the necessary updates to mitigate this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
