CVE-2024-30931: XSS
Published Jun 25, 2024
·Updated
Stored Cross Site Scripting vulnerability in Emby Media Server Emby Media Server 4.8.3.0 allows a remote attacker to escalate privileges via the notifications.html component.
Affected Software
1 affected component
Emby Media Server
Event History
Jun 25, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-30931?
The severity of CVE-2024-30931 is considered high due to the potential for privilege escalation by remote attackers.
2
How do I fix CVE-2024-30931?
To fix CVE-2024-30931, upgrade Emby Media Server to version 4.8.3.1 or later, which patches the vulnerability.
3
What is the impact of CVE-2024-30931?
CVE-2024-30931 allows attackers to execute stored cross-site scripting, potentially leading to unauthorized access and privilege escalation.
4
Which versions of Emby Media Server are affected by CVE-2024-30931?
CVE-2024-30931 affects Emby Media Server version 4.8.3.0 and prior versions.
5
Can CVE-2024-30931 be exploited without authentication?
Yes, CVE-2024-30931 can be exploited by unauthenticated remote attackers via the notifications.html component.