Sploitus

CVE-2023-48702

No indexed exploits for CVE-2023-48702 yet

Jellyfin is a system for managing and streaming media. Prior to version 10.8.13, the `/System/MediaEncoder/Path` endpoint executes an arbitrary file using `ProcessStartInfo` via the `ValidateVersion` function. A malicious administrator can setup a network share and supply a UNC path to `/System/MediaEncoder/Path` which points to an executable on the network share, causing Jellyfin server to run the executable in the local context. The endpoint was removed in version 10.8.13.

Affected products
Jellyfin
Jellyfin
< 10.8.13
Fix
Available
CVSS 3.1
7.2 HIGH
EPSS
1.2% (66th percentile)
Weakness
CWE-77
NVD status
Modified
Published
2023-12-13
CVE-2023-48702 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2023-48702 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2023-48702 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.