Количество 3
Количество 3
CVE-2023-23636
около 3 лет назад
In Jellyfin 10.8.x through 10.8.3, the name of a playlist is vulnerable to stored XSS. This allows an attacker to steal access tokens from the localStorage of the victim.
CVSS3: 5.4
EPSS: Низкий
CVE-2023-23636
около 3 лет назад
In Jellyfin 10.8.x through 10.8.3, the name of a playlist is vulnerabl ...
CVSS3: 5.4
EPSS: Низкий
GHSA-2h5r-cqfc-45v6
около 3 лет назад
Jellyfin Web Cross-Site Scripting (XSS) via Playlist Name
CVSS3: 5.4
EPSS: Низкий
Уязвимостей на страницу
20
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-23636 In Jellyfin 10.8.x through 10.8.3, the name of a playlist is vulnerable to stored XSS. This allows an attacker to steal access tokens from the localStorage of the victim. | CVSS3: 5.4 | 1% Низкий | около 3 лет назад | |
CVE-2023-23636 In Jellyfin 10.8.x through 10.8.3, the name of a playlist is vulnerabl ... | CVSS3: 5.4 | 1% Низкий | около 3 лет назад | |
GHSA-2h5r-cqfc-45v6 Jellyfin Web Cross-Site Scripting (XSS) via Playlist Name | CVSS3: 5.4 | 1% Низкий | около 3 лет назад |
Уязвимостей на страницу
20