Lee Peuker
5 exploits
Active since Oct 2025
Movary has Authenticated SSRF via Jellyfin Server URL Verification that Allows Internal Network Probing
CVSS 7.7
Authenticated Movary User Can Self-Escalate to Administrator via PUT /settings/users/{userId} by Setting isAdmin=true
CVSS 8.8
Movary User Management (/settings/users) has Authorization Bypass that Allows Low-Privileged Users to Enumerate All Users and Create Administrator Accounts
CVSS 8.8
Leepeuker Movary < 0.69.0 - Open Redirect
CVSS 6.1
Leepeuker Movary < 0.69.0 - Open Redirect
CVSS 6.1