VYPR
Vendor

Pymedusa

Products
2
CVEs
3
Across products
4
Status
Private

Products

2

Recent CVEs

3
  • CVE-2023-50258MedDec 22, 2023
    risk 0.35cvss 5.3epss 0.01

    Medusa is an automatic video library manager for TV shows. Versions prior to 1.0.19 are vulnerable to unauthenticated blind server-side request forgery (SSRF). The `testDiscord` request handler in `medusa/server/web/home/handler.py` does not validate the user-controlled…

  • CVE-2023-50259MedDec 22, 2023
    risk 0.34cvss 5.3epss 0.01

    Medusa is an automatic video library manager for TV shows. Versions prior to 1.0.19 are vulnerable to unauthenticated blind server-side request forgery (SSRF). The `testslack` request handler in `medusa/server/web/home/handler.py` does not validate the user-controlled…

  • CVE-2023-28627HigMar 27, 2023
    risk 0.00cvss 8.3epss 0.01

    pymedusa is an automatic video library manager for TV Shows. In versions prior 1.0.12 an attacker with access to the web interface can update the git executable path in /config/general/ > advanced settings with arbitrary OS commands. An attacker may exploit this vulnerability to…