VDB
Sign up
MEDIUM6.1

GHSA-x2gw-85w6-fjjw

Cross-site scripting in demos/demo.mysqli.php in getID3

Quick fix

GHSA-x2gw-85w6-fjjw — james-heinrich/getid3: upgrade to the fixed version with the command below.

composer require james-heinrich/getid3:^1.9.21

Details

Cross-site scripting (XSS) vulnerability in demos/demo.mysqli.php in getID3 1.X and v2.0.0-beta allows remote attackers to inject arbitrary web script or HTML via the showtagfiles parameter.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/james-heinrich/getid3
Introduced in: 1.0.0Fixed in: 1.9.21
Fixcomposer require james-heinrich/getid3:^1.9.21

References