CVE-2015-8310
Published Mar 27, 2017Cross-site scripting (XSS) vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to inject arbitrary web script or HTML via the playlistname field when cre…
Vendor archive
2 CVEs tagged to vendor fomori — 0 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.
Cross-site scripting (XSS) vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to inject arbitrary web script or HTML via the playlistname field when cre…
Directory traversal vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to read arbitrary files via the "value" parameter to "download."