Jump to content

Recommended Posts

igeoorge
Posted

Friends,

We just noticed an XSS vulnerability

I am at version: 4.5.4.0

Has this already been fixed?

11título.png

  • Like 1
Carlo
Posted

Hi, what are you trying to show us?

Posted
17 minutes ago, cayars said:

Hi, what are you trying to show us?

According to the screenshot, foreign Javascript is  being injected through the url and executed by the browser as if it were part of the Emby web app.

Posted

Testing on 4.6, with what appears to be the same url you're testing with, I do not get the alert dialog.

Posted
16 hours ago, Luke said:

Testing on 4.6, with what appears to be the same url you're testing with, I do not get the alert dialog.

FWIW, I also get an "access denied" on latest stable.

igeoorge
Posted

Thanks for your attention friends

In the latest version the vulnerability does not occur.

  • Like 1
Posted
2 hours ago, igeoorge said:

Thanks for your attention friends

In the latest version the vulnerability does not occur.

Thanks for the feedback.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...