CVE-2023-23636
03.02.2023, 01:15
In Jellyfin 10.8.x through 10.8.3, the name of a playlist is vulnerable to stored XSS. This allows an attacker to steal access tokens from the localStorage of the victim.
Vendor | Product | Version |
---|---|---|
jellyfin | jellyfin | 10.8.0 ≤ 𝑥 ≤ 10.8.3 |
𝑥
= Vulnerable software versions
References