MEDIUM6.1
GHSA-x2gw-85w6-fjjw
Cross-site scripting in demos/demo.mysqli.php in getID3
Quick fix
GHSA-x2gw-85w6-fjjw — james-heinrich/getid3: upgrade to the fixed version with the command below.
composer require james-heinrich/getid3:^1.9.21Details
Cross-site scripting (XSS) vulnerability in demos/demo.mysqli.php in getID3 1.X and v2.0.0-beta allows remote attackers to inject arbitrary web script or HTML via the showtagfiles parameter.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/james-heinrich/getid3
Introduced in:
1.0.0Fixed in: 1.9.21Fix
composer require james-heinrich/getid3:^1.9.21