VendorsPopcorn Time Projectpopcorn_time0.4.7
Vulnerabilities

Popcorn Time Project Popcorn Time 0.4.7

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2022-25229
Popcorn Time 0.4.7 has a Stored XSS in the 'Movies API Server(s)' field via the 'settings' page. The 'nodeIntegration' configuration is set to on which allows the 'webpage' to use 'NodeJs' features, an attacker can leverage this to run OS commands.
Published 2022-05-20 · Modified
5.4EPSS 0.006