Loading HuntDB...

Plex Media Server Remote Code Execution Vulnerability

Added March 10, 2023 Due March 31, 2023 CVE-2020-5741
Overdue Plex / Media Server CWE-502

Description

Plex Media Server contains a remote code execution vulnerability that allows an attacker with access to the server administrator's Plex account to upload a malicious file via the Camera Upload feature and have the media server execute it.

Required Action

Apply updates per vendor instructions.

References

Additional Information

Catalog Version
2025.01.24
Catalog Released
Jan. 24, 2025
Days Until Due
0 days
Last Updated
7 months, 1 week ago