A vulnerability was identified in jxxghp MoviePilot up to 2.13.5. The affected element is an unknown function of the file /jxxghp/MoviePilot of the component Application API. The manipulation leads to improper authorization. Remote exploitation of the attack is possible. The identifier of the patch is dc2b6910a423b3bfadeffaa303e1ba75cfb33900. This issue affects users of jxxghp MoviePilot up to 2.13.5. The [truncated]
MoviePilot v2 contains a server-side request forgery (SSRF) vulnerability in the image proxy endpoint. The vulnerability exists because the SecurityUtils.is_safe_url function performs only domain-membership checking without validating that resolved addresses are not private, loopback, or link-local ranges. An authenticated attacker with a valid resource_token cookie can supply a URL whose domain matches t [truncated]