PT-2019-20125 · Plex · Tautulli
Published
2019-02-19
·
Updated
2019-02-19
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Tautulli version 2.1.26
Description
The issue concerns a problem with handling a crafted Plex username, which leads to XSS when constructing the History page, specifically affecting the
data/interfaces/default/history.html file.Recommendations
For Tautulli version 2.1.26, consider restricting the use of the History page until a patch is available, and avoid using crafted Plex usernames to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tautulli