PT-2019-20125 · Plex · Tautulli

Published

2019-02-19

·

Updated

2019-02-19

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Tautulli version 2.1.26
Description The issue concerns a problem with handling a crafted Plex username, which leads to XSS when constructing the History page, specifically affecting the data/interfaces/default/history.html file.
Recommendations For Tautulli version 2.1.26, consider restricting the use of the History page until a patch is available, and avoid using crafted Plex usernames to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

PYSEC-2019-255

Affected Products

Tautulli