—
PYSEC-2017-100
Quick fix
PYSEC-2017-100 — cherrymusic: upgrade to the fixed version with the command below.
pip install --upgrade 'cherrymusic>=62dec34a1ea0741400dd6b6c660d303dcd651e86'Details
Cross-site scripting (XSS) vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to inject arbitrary web script or HTML via the playlistname field when creating a new playlist.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/cherrymusic
Introduced in:
0Fixed in: 62dec34a1ea0741400dd6b6c660d303dcd651e86Fix
pip install --upgrade 'cherrymusic>=62dec34a1ea0741400dd6b6c660d303dcd651e86'