In Emby Server 4.6.7.0, the playlist name field is vulnerable to XSS stored where it is possible to steal the administrator access token and flip or steal the media server administrator account.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-38942 | In Emby Server 4.6.7.0, the playlist name field is vulnerable to XSS stored where it is possible to steal the administrator access token and flip or steal the media server administrator account. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 18 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-18T13:24:24.550Z
Reserved: 2022-07-18T00:00:00.000Z
Link: CVE-2022-36223
Updated: 2024-08-03T10:00:04.341Z
Status : Modified
Published: 2022-12-16T14:15:09.097
Modified: 2025-04-18T14:15:18.570
Link: CVE-2022-36223
No data.
OpenCVE Enrichment
No data.
EUVD