CVE-2023-23636
EUVD-2023-2772403.02.2023, 01:15
In Jellyfin 10.8.x through 10.8.3, the name of a playlist is vulnerable to stored XSS. This allows an attacker to steal access tokens from the localStorage of the victim.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| jellyfin | jellyfin | 10.8.0 ≤ 𝑥 ≤ 10.8.3 |
𝑥
= Vulnerable software versions
References