PlexRipper is a cross-platform media downloader for Plex. PlexRipper’s open CORS policy allows attackers to gain sensitive information from PlexRipper by getting the user to access the attacker’s domain. This allows an attacking website to access the /api/PlexAccount endpoint and steal the user’s Plex login. This vulnerability is fixed in 0.24.0.
Metrics
Affected Vendors & Products
References
History
Mon, 02 Dec 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Plexripper Project
Plexripper Project plexripper |
|
CPEs | cpe:2.3:a:plexripper_project:plexripper:*:*:*:*:*:*:*:* | |
Vendors & Products |
Plexripper Project
Plexripper Project plexripper |
|
Metrics |
ssvc
|
Mon, 02 Dec 2024 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | PlexRipper is a cross-platform media downloader for Plex. PlexRipper’s open CORS policy allows attackers to gain sensitive information from PlexRipper by getting the user to access the attacker’s domain. This allows an attacking website to access the /api/PlexAccount endpoint and steal the user’s Plex login. This vulnerability is fixed in 0.24.0. | |
Title | PlexRipper allows API leak due to open CORS policy | |
Weaknesses | CWE-942 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-12-02T16:41:26.846Z
Updated: 2024-12-02T17:22:07.037Z
Reserved: 2024-10-18T13:43:23.456Z
Link: CVE-2024-49763

Updated: 2024-12-02T17:21:56.988Z

Status : Received
Published: 2024-12-02T17:15:11.830
Modified: 2024-12-02T17:15:11.830
Link: CVE-2024-49763

No data.