Launchpad.net

CVE 2022-35910

In Jellyfin before 10.8, stored XSS allows theft of an admin access token.

See the CVE page on Mitre.org for more details.