CVE-2014-9304 is a vulnerability in Plex Media Server
Published on December 7, 2014
Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary administrative actions via multiple crafted X-Plex-Url headers to system/proxy, which are inconsistently processed by the request handler in the backend web server.
Products Associated with CVE-2014-9304
Want to know whenever a new CVE is published for Plex Media Server? stack.watch will email you.
Exploit Probability
EPSS
3.39%
Percentile
87.16%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.