VDB
Sign up
—

PYSEC-2017-100

Quick fix

PYSEC-2017-100 — cherrymusic: upgrade to the fixed version with the command below.

pip install --upgrade 'cherrymusic>=62dec34a1ea0741400dd6b6c660d303dcd651e86'

Details

Cross-site scripting (XSS) vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to inject arbitrary web script or HTML via the playlistname field when creating a new playlist.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/cherrymusic
Introduced in: 0Fixed in: 62dec34a1ea0741400dd6b6c660d303dcd651e86
Fixpip install --upgrade 'cherrymusic>=62dec34a1ea0741400dd6b6c660d303dcd651e86'

References