Количество 3
Количество 3
CVE-2023-23635
около 3 лет назад
In Jellyfin 10.8.x through 10.8.3, the name of a collection is vulnerable to stored XSS. This allows an attacker to steal access tokens from the localStorage of the victim.
CVSS3: 5.4
EPSS: Низкий
CVE-2023-23635
около 3 лет назад
In Jellyfin 10.8.x through 10.8.3, the name of a collection is vulnera ...
CVSS3: 5.4
EPSS: Низкий
GHSA-749c-pc87-4qcw
около 3 лет назад
Jellyfin Web Cross-Site Scripting (XSS) via Collection Name
CVSS3: 5.4
EPSS: Низкий
Уязвимостей на страницу
20
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-23635 In Jellyfin 10.8.x through 10.8.3, the name of a collection is vulnerable to stored XSS. This allows an attacker to steal access tokens from the localStorage of the victim. | CVSS3: 5.4 | 1% Низкий | около 3 лет назад | |
CVE-2023-23635 In Jellyfin 10.8.x through 10.8.3, the name of a collection is vulnera ... | CVSS3: 5.4 | 1% Низкий | около 3 лет назад | |
GHSA-749c-pc87-4qcw Jellyfin Web Cross-Site Scripting (XSS) via Collection Name | CVSS3: 5.4 | 1% Низкий | около 3 лет назад |
Уязвимостей на страницу
20