Stored XSS Vulnerability in Jellyfin Media Server by Jellyfin
CVE-2023-23636

5.4MEDIUM

Key Information:

Vendor

Jellyfin

Status
Vendor
CVE Published:
3 February 2023

What is CVE-2023-23636?

A stored XSS vulnerability exists in Jellyfin Media Server versions 10.8.x through 10.8.3, specifically affecting the naming functionality of playlists. This vulnerability allows malicious actors to inject scripts into the playlist name, which can subsequently be executed in the browsers of users who access the affected playlists. As a result, the attacker may gain unauthorized access to access tokens stored in the victim's localStorage, facilitating further malicious activities.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.