Jump to content

Cross-site scripting vulnerability?


Recommended Posts

Posted

HI, that's already patched in the beta. I think we'll be doing a 4.7.14 release so we can get that fix included as well.

This is only high in severity if you actually click on a link that takes you to your server and contains javascript in the url. That means someone has to send you that link first, and then you have to decide to click on it. Since you are the master of your own server, you're most likely not going to need someone to send you a link in order to be able to reach it.

  • Like 1
Posted (edited)

It is for links in forums with links to local servers i.e. localhost, if you click on it on the machine running emby it will probably work.

 

 

 

Edited by TeamB
  • 2 weeks later...
Posted
On 8/15/2023 at 4:28 PM, Luke said:

HI, that's already patched in the beta. I think we'll be doing a 4.7.14 release so we can get that fix included as well.

 

Not a big deal for me but is this included?

image.png.6b87185bbe7b4da4392c4530465d82b7.png

There is no mention of this!

I just wish @Lukewould give better descriptions about what the releases includes  (or a link for more details)

Thanks.

Posted

Yes it is. I'll add this to the notes.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...