Description
Emby Server is a personal media server. Prior to version 4.8.1.0 and prior to Beta version 4.9.0.0-beta, a malicious user can send an authentication request with a manipulated X-Emby-Client value, which gets added to the devices section of the admin dashboard without sanitization. This issue has been patched in version 4.8.1.0 and Beta version 4.9.0.0-beta.
Problem types
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-116: Improper Encoding or Escaping of Output
Product status
Emby Server Beta (Web App) < 4.9.0.0-beta
References
github.com/...curity/security/advisories/GHSA-2gwc-988r-2r7x
github.com/...curity/security/advisories/GHSA-2gwc-988r-2r7x