Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-43833 | PlexRipper is a cross-platform media downloader for Plex. PlexRipper’s open CORS policy allows attackers to gain sensitive information from PlexRipper by getting the user to access the attacker’s domain. This allows an attacking website to access the /api/PlexAccount endpoint and steal the user’s Plex login. This vulnerability is fixed in 0.24.0. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 02 Dec 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Plexripper Project
Plexripper Project plexripper |
|
| CPEs | cpe:2.3:a:plexripper_project:plexripper:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Plexripper Project
Plexripper Project plexripper |
|
| Metrics |
ssvc
|
Mon, 02 Dec 2024 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PlexRipper is a cross-platform media downloader for Plex. PlexRipper’s open CORS policy allows attackers to gain sensitive information from PlexRipper by getting the user to access the attacker’s domain. This allows an attacking website to access the /api/PlexAccount endpoint and steal the user’s Plex login. This vulnerability is fixed in 0.24.0. | |
| Title | PlexRipper allows API leak due to open CORS policy | |
| Weaknesses | CWE-942 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-12-02T17:22:07.037Z
Reserved: 2024-10-18T13:43:23.456Z
Link: CVE-2024-49763
Updated: 2024-12-02T17:21:56.988Z
Status : Received
Published: 2024-12-02T17:15:11.830
Modified: 2024-12-02T17:15:11.830
Link: CVE-2024-49763
No data.
OpenCVE Enrichment
No data.
EUVD