top of page
perceptive_background_267k.jpg

Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can trigger server-side reque…

Published:

17 april 2026 om 22:00:00

Alert date:

18 april 2026 om 01:02:17

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies

Movary, a self-hosted movie tracking web application, contains a Server-Side Request Forgery (SSRF) vulnerability in versions prior to 0.71.1. The vulnerability exists in the POST /settings/jellyfin/server-url-verify endpoint which accepts user-controlled URLs without proper validation. Authenticated users can exploit this to make server-side requests to arbitrary internal targets, enabling internal network reconnaissance, host discovery, port scanning, and service fingerprinting. The vulnerability could potentially be used to access internal administrative services or cloud metadata endpoints not directly accessible from external networks. The issue has been fixed in version 0.71.1.

Technical details

Mitigation steps:

Affected products:

Movary

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page