Subscribe via feed.

Emby MediaServer 3.2.5 Reflected Cross Site Scripting

Posted by deepcore on May 2, 2017 – 8:45 am

Emby MediaServer version 3.2.5 suffers from a XSS issue due to a failure to properly sanitize user-supplied input to the URL path filename when handling ‘not found’ errors. Attackers can exploit this weakness to execute arbitrary HTML and script code in a user’s browser session.


This post is under “exploit” and has no respond so far.
If you enjoy this article, make sure you subscribe to my RSS Feed.

Post a reply

You must be logged in to post a comment.