PlexRipper is a cross-platform media downloader for Plex. PlexRipper’s open CORS policy allows attackers to gain sensitive information from PlexRipper by getting the user to access the attacker’s domain. This allows an attacking website to access the /api/PlexAccount endpoint and steal the user’s Plex login. This vulnerability is fixed in 0.24.0.
History

Mon, 02 Dec 2024 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Plexripper Project
Plexripper Project plexripper
CPEs cpe:2.3:a:plexripper_project:plexripper:*:*:*:*:*:*:*:*
Vendors & Products Plexripper Project
Plexripper Project plexripper
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 02 Dec 2024 17:00:00 +0000

Type Values Removed Values Added
Description PlexRipper is a cross-platform media downloader for Plex. PlexRipper’s open CORS policy allows attackers to gain sensitive information from PlexRipper by getting the user to access the attacker’s domain. This allows an attacking website to access the /api/PlexAccount endpoint and steal the user’s Plex login. This vulnerability is fixed in 0.24.0.
Title PlexRipper allows API leak due to open CORS policy
Weaknesses CWE-942
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-12-02T16:41:26.846Z

Updated: 2024-12-02T17:22:07.037Z

Reserved: 2024-10-18T13:43:23.456Z

Link: CVE-2024-49763

cve-icon Vulnrichment

Updated: 2024-12-02T17:21:56.988Z

cve-icon NVD

Status : Received

Published: 2024-12-02T17:15:11.830

Modified: 2024-12-02T17:15:11.830

Link: CVE-2024-49763

cve-icon Redhat

No data.