Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call with a transient access token.
Plex Media Server versions through 1.42.2.10156 contain an authorization bypass vulnerability (CWE-863) allowing attackers to escalate transient access tokens to permanent tokens via the /myplex/account endpoint. With a CVSS score of 8.5 and active exploits available, this critical flaw enables persistent unauthorized access to media servers and user accounts.
في طابور التحليل الذكي
سيتم تحليل هذا CVE تلقائياً في المهام المجدولة.