CVE-2023-30626
Jellyfin is a free-software media system. Versions starting with 10.8.0 and prior to 10.8.10 and prior have a directory traversal vulnerability inside the `ClientLogController`, specifically `/ClientLog/Document`. When combined with a cross-site scripting vulnerability (CVE-2023-30627), this can result in file write and arbitrary code execution. Version 10.8.10 has a patch for this issue. There are no known workarounds.
- Affected products
- Jellyfin
- Jellyfin
- < 10.8.10
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 2.0% (79th percentile)
- Weakness
- CWE-22
- NVD status
- Modified
- Published
- 2023-04-24
CVE-2023-30626 at NVD
1 known exploit for CVE-2023-30626
Proof-of-concept code and exploit modules indexed by Sploitus