CVE-2014-9304

Plex Media Server <0.9.9.3 - SSRF

Title source: llm
STIX 2.1

Description

Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary administrative actions via multiple crafted X-Plex-Url headers to system/proxy, which are inconsistently processed by the request handler in the backend web server.

Exploits (1)

exploitdb WRITEUP
by SEC Consult · textwebappsmultiple
https://www.exploit-db.com/exploits/31983

Scores

EPSS 0.0339
EPSS Percentile 87.4%

Details

CWE
CWE-264
Status published
Products (1)
plex/media_server < 0.9.9.2
Published Dec 07, 2014
Tracked Since Feb 18, 2026