Описание
In Jellyfin 10.8.x through 10.8.3, the name of a playlist is vulnerable to stored XSS. This allows an attacker to steal access tokens from the localStorage of the victim.
Ссылки
- ExploitIssue TrackingPatchThird Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- ExploitIssue TrackingPatchThird Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 10.8.0 (включая) до 10.8.3 (включая)
cpe:2.3:a:jellyfin:jellyfin:*:*:*:*:*:*:*:*
EPSS
Процентиль: 67%
0.00532
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-79
CWE-79
Связанные уязвимости
CVSS3: 5.4
debian
около 3 лет назад
In Jellyfin 10.8.x through 10.8.3, the name of a playlist is vulnerabl ...
CVSS3: 5.4
github
около 3 лет назад
Jellyfin Web Cross-Site Scripting (XSS) via Playlist Name
EPSS
Процентиль: 67%
0.00532
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-79
CWE-79