PyPI package
cherrymusic
pkg:pypi/cherrymusic
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2015-8310 | Med | 5.4 | < 0.36.0 | 0.36.0 | Mar 27, 2017 | Cross-site scripting (XSS) vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to inject arbitrary web script or HTML via the playlistname field when creating a new playlist. | |
| CVE-2015-8309 | Med | 4.3 | < 0.36.0 | 0.36.0 | Mar 27, 2017 | Directory traversal vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to read arbitrary files via the "value" parameter to "download." |
- affected < 0.36.0fixed 0.36.0
Cross-site scripting (XSS) vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to inject arbitrary web script or HTML via the playlistname field when creating a new playlist.
- affected < 0.36.0fixed 0.36.0
Directory traversal vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to read arbitrary files via the "value" parameter to "download."