Vulnerability Details CVE-2014-9304
Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary administrative actions via multiple crafted X-Plex-Url headers to system/proxy, which are inconsistently processed by the request handler in the backend web server.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.02
EPSS Ranking 83.0%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2014-9304
-
cpe:2.3:a:plex:media_server:-
-
cpe:2.3:a:plex:media_server:0.9.9.2