Description
PlexRipper is a cross-platform media downloader for Plex. PlexRipper’s open CORS policy allows attackers to gain sensitive information from PlexRipper by getting the user to access the attacker’s domain. This allows an attacking website to access the /api/PlexAccount endpoint and steal the user’s Plex login. This vulnerability is fixed in 0.24.0.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-43833 | PlexRipper is a cross-platform media downloader for Plex. PlexRipper’s open CORS policy allows attackers to gain sensitive information from PlexRipper by getting the user to access the attacker’s domain. This allows an attacking website to access the /api/PlexAccount endpoint and steal the user’s Plex login. This vulnerability is fixed in 0.24.0. |
References
History
Mon, 02 Dec 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Plexripper Project
Plexripper Project plexripper |
|
| CPEs | cpe:2.3:a:plexripper_project:plexripper:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Plexripper Project
Plexripper Project plexripper |
|
| Metrics |
ssvc
|
Mon, 02 Dec 2024 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PlexRipper is a cross-platform media downloader for Plex. PlexRipper’s open CORS policy allows attackers to gain sensitive information from PlexRipper by getting the user to access the attacker’s domain. This allows an attacking website to access the /api/PlexAccount endpoint and steal the user’s Plex login. This vulnerability is fixed in 0.24.0. | |
| Title | PlexRipper allows API leak due to open CORS policy | |
| Weaknesses | CWE-942 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-12-02T17:22:07.037Z
Reserved: 2024-10-18T13:43:23.456Z
Link: CVE-2024-49763
Updated: 2024-12-02T17:21:56.988Z
Status : Deferred
Published: 2024-12-02T17:15:11.830
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-49763
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD