Lucene search

K
cvelistMitreCVELIST:CVE-2023-23635
HistoryFeb 03, 2023 - 12:00 a.m.

CVE-2023-23635

2023-02-0300:00:00
mitre
www.cve.org
3
jellyfin
collection
vulnerability
stored xss
access tokens
localstorage

EPSS

0.001

Percentile

27.1%

In Jellyfin 10.8.x through 10.8.3, the name of a collection is vulnerable to stored XSS. This allows an attacker to steal access tokens from the localStorage of the victim.

EPSS

0.001

Percentile

27.1%

Related for CVELIST:CVE-2023-23635