VulnerAlert



APPLICATION
DATABASE
PYTHON
10-09-2025 14:51

CVE-2025-58761 Vulnerabilidad documentada

Sin puntuación
Tags
#python
#sql
#data
#server
#order
#join
#image
#db
#config
#admin
#database
#application
#/sql(.*)server/iU
#sql server
#attackers
#authenticated
#bypass
#arbitrary
#vulnerable
#privilege
#pass
#password
#obtain
#issue
#fix
#allow
#attack
Descripción
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. The `real_pms_image_proxy` endpoint in Tautulli v2.15.3 prior vulnerable to path traversal, allowing unauthenticated attackers read arbitrary files from the application server's filesystem. used fetch an image directly backing be fetched specified through `img` URL parameter, which can either or file path. There some validation ensuring that begins with prefix `interfaces/default/images` order served local However this bypassed by passing parameter valid prefix, then adjoining traversal characters reach outside of intended directories. An attacker exfiltrate on system, including `tautulli.db` SQLite database containing active JWT tokens, as well `config.ini` contains hashed admin password, token secret, Server connection details. If password cracked, if present database, escalate their privileges obtain administrative control over application. Version 2.16.0 fix issue.
https://github.com/Tautulli/Tautulli/commit/ec77a70aafc555e1aad0d9981f719d1200c117f1
https://github.com/Tautulli/Tautulli/security/advisories/GHSA-r732-m675-wj7w
https://github.com/Tautulli/Tautulli/security/advisories/GHSA-r732-m675-wj7w
Referencia
Link externo
Ver detalles

Fuente
https://nvd.nist.gov/vuln/detail/CVE-2025-58761
Resultados similares
Coincidentes en almenos en 50% de los tags
10-09-2025 CVE-2025-43725
Dell PowerProtect Data Manager, Generic Application Agent, version(s) 19.19 and 19.20, contain(...
Ver información
10-09-2025 CVE-2024-34351
Next.js is a React framework that can provide building blocks to create web applications. A Ser...
Ver información
Icons made by Freepik from www.flaticon.com
Este Proyecto fue cofinanciado por el Consejo Nacional de Ciencia y Tecnología (CONACYT) a través del PROINNOVA 2021/2023
Proyecto realizado por