plex media-server CVE-2019-19141 is a vulnerability in Plex Media Server
Published on December 19, 2019

The Camera Upload functionality in Plex Media Server through 1.18.2.2029 allows remote authenticated users to write files anywhere the user account running the Plex Media Server has permissions. This allows remote code execution via a variety of methods, such as (on a default Ubuntu installation) creating a .ssh folder in the plex user's home directory via directory traversal, uploading an SSH authorized_keys file there, and logging into the host as the Plex user via SSH.

NVD


Products Associated with CVE-2019-19141

Want to know whenever a new CVE is published for Plex Media Server? stack.watch will email you.

 

Exploit Probability

EPSS
1.85%
Percentile
82.87%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.