Back to directory
WRITEUP #2488

CVE-2022–35909 / CVE-2022–35910, Incorrect Access Control and XSS Stored to Jellyfin

XSSBroken Access Control
byDan Barros
Program
jellyfin
Published
Jul 18, 2022
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://medium.com/stolabs/cve-2022-35909-cve-2022-35910-incorrect-access-control-and-xss-stored-to-jellyfin-967359c91058
RELATED WRITEUPS
Self-XSS to ATO via Site Features
XSSSelf-XSS
How 100% Manual Hacking (Without Even Kali And Burp) Led To 2 Medium Vulnerabilities On YesWeHack
XSS
Basic HTTP Authentication Risk: Uncovering pyspider Vulnerabilities
XSSReflected XSS
Bypassing CSP via URL Parser Confusions : XSS on Netlify’s Image CDN
XSSCSP bypass
A Story About How I Found XSS in ASUS
XSS

Built with ❤️ by Shubham Rawat