This exploit demonstrates a directory traversal vulnerability in Emby MediaServer versions 3.2.5 and below, allowing unauthorized file disclosure via crafted HTTP requests to the 'swagger-ui' endpoint. The PoC includes example requests for Windows and Linux systems.
Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target:Emby MediaServer 3.2.5 and below
No auth needed
Prerequisites:Network access to the Emby server · Swagger UI endpoint enabled