PT-2022-23265 · Emby · Emby Server

Published

2022-12-16

·

Updated

2022-12-20

·

CVE-2022-36223

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Emby Server version 4.6.7.0
Description The issue affects the playlist name field, which is vulnerable to stored XSS. This vulnerability allows for the potential theft of the administrator access token, enabling attackers to either flip or steal the media server administrator account.
Recommendations For Emby Server version 4.6.7.0, consider disabling the playlist name field until a patch is available to prevent exploitation of the stored XSS vulnerability. Restrict access to the administrator account and monitor for any suspicious activity to minimize the risk of account theft.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-36223

Affected Products

Emby Server