Vulnerabilities
Vulnerable Software
Fomori:  >> Cherrymusic  >> 0.35.2  Security Vulnerabilities
Directory traversal vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to read arbitrary files via the "value" parameter to "download."
CVSS Score
4.3
EPSS Score
0.066
Published
2017-03-27
Cross-site scripting (XSS) vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to inject arbitrary web script or HTML via the playlistname field when creating a new playlist.
CVSS Score
5.4
EPSS Score
0.002
Published
2017-03-27


Contact Us

Shodan ® - All rights reserved