Medium severity5.4NVD Advisory· Published Aug 19, 2022· Updated Jun 17, 2026
CVE-2022-35910
CVE-2022-35910
Description
In Jellyfin before 10.8, stored XSS allows theft of an admin access token.
Affected products
3Patches
Vulnerability mechanics
References
3- github.com/jellyfin/jellyfin/pull/7569/filesnvdPatchThird Party Advisory
- docs.google.com/document/d/1cBXQrokCvWxKET4BKi3ZLtVp5gst6-MrGPgMKpfXw8Y/editnvdExploitThird Party Advisory
- medium.com/stolabs/cve-2022-35909-cve-2022-35910-incorrect-access-control-and-xss-stored-to-jellyfin-967359c91058nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.