Описание
In Jellyfin 10.8.x through 10.8.3, the name of a playlist is vulnerable to stored XSS. This allows an attacker to steal access tokens from the localStorage of the victim.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| jellyfin | itp | package |
Связанные уязвимости
CVSS3: 5.4
nvd
около 3 лет назад
In Jellyfin 10.8.x through 10.8.3, the name of a playlist is vulnerable to stored XSS. This allows an attacker to steal access tokens from the localStorage of the victim.
CVSS3: 5.4
github
около 3 лет назад
Jellyfin Web Cross-Site Scripting (XSS) via Playlist Name