CVE-2022-35910: XSS
In Jellyfin before 10.8, stored XSS allows theft of an admin access token.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-35910?
CVE-2022-35910 is a vulnerability in Jellyfin before version 10.8 that allows for stored cross-site scripting (XSS) attacks and theft of an admin access token.
What is the severity of CVE-2022-35910?
CVE-2022-35910 has a severity rating of medium, with a CVSS score of 5.4.
How does CVE-2022-35910 impact Jellyfin?
CVE-2022-35910 allows an attacker to perform stored XSS attacks, which can result in the theft of an admin access token in Jellyfin.
How can I fix the CVE-2022-35910 vulnerability in Jellyfin?
To fix the CVE-2022-35910 vulnerability in Jellyfin, it is recommended to update to version 10.8 or later, which includes the necessary security patches.
Where can I find more information about CVE-2022-35910?
You can find more information about CVE-2022-35910 in the following references: [Link 1](https://docs.google.com/document/d/1cBXQrokCvWxKET4BKi3ZLtVp5gst6-MrGPgMKpfXw8Y/edit), [Link 2](https://github.com/jellyfin/jellyfin/pull/7569/files), [Link 3](https://medium.com/stolabs/cve-2022-35909-cve-2022-35910-incorrect-access-control-and-xss-stored-to-jellyfin-967359c91058)