Lee Peuker
5 exploits
Active since Oct 2025
Movary has Authenticated SSRF via Jellyfin Server URL Verification that Allows Internal Network Probing
CVSS 7.7
Authenticated Movary User Can Self-Escalate to Administrator via PUT /settings/users/{userId} by Setting isAdmin=true
CVSS 8.8
Movary User Management (/settings/users) has Authorization Bypass that Allows Low-Privileged Users to Enumerate All Users and Create Administrator Accounts
CVSS 8.8
Movary <= 0.68.0 - Open Redirect via HTTP Referer Header
CVSS 6.1
Movary < 0.69.0 - Open Redirect via Login Page Redirect Parameter
CVSS 6.1