Описание
In Jellyfin 10.8.x through 10.8.3, the name of a collection is vulnerable to stored XSS. This allows an attacker to steal access tokens from the localStorage of the victim.
Ссылки
- Issue TrackingThird Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- Issue TrackingThird Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 10.8.0 (включая) до 10.8.3 (включая)
cpe:2.3:a:jellyfin:jellyfin:*:*:*:*:*:*:*:*
EPSS
Процентиль: 67%
0.00538
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-79
CWE-79
Связанные уязвимости
CVSS3: 5.4
debian
около 3 лет назад
In Jellyfin 10.8.x through 10.8.3, the name of a collection is vulnera ...
CVSS3: 5.4
github
около 3 лет назад
Jellyfin Web Cross-Site Scripting (XSS) via Collection Name
EPSS
Процентиль: 67%
0.00538
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-79
CWE-79