In Jellyfin before 10.8, the /users endpoint has incorrect access control for admin functionality. This lack of access control can be leveraged to performe a cross site scripting attack.
References
https://nvd.nist.gov/vuln/detail/CVE-2022-35909
https…