Vulnerability Description
Cross-site scripting (XSS) vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to inject arbitrary web script or HTML via the playlistname field when creating a new playlist.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fomori | Cherrymusic | <= 0.35.2 |
Related Weaknesses (CWE)
References
- http://www.fomori.org/cherrymusic/Changes.htmlRelease NotesVendor Advisory
- http://www.securityfocus.com/bid/97148
- https://github.com/devsnd/cherrymusic/commit/62dec34a1ea0741400dd6b6c660d303dcd6PatchThird Party Advisory
- https://github.com/devsnd/cherrymusic/issues/598Third Party Advisory
- http://www.fomori.org/cherrymusic/Changes.htmlRelease NotesVendor Advisory
- http://www.securityfocus.com/bid/97148
- https://github.com/devsnd/cherrymusic/commit/62dec34a1ea0741400dd6b6c660d303dcd6PatchThird Party Advisory
- https://github.com/devsnd/cherrymusic/issues/598Third Party Advisory
FAQ
What is CVE-2015-8310?
CVE-2015-8310 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Cross-site scripting (XSS) vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to inject arbitrary web script or HTML via the playlistname field when creating a new playlist.
How severe is CVE-2015-8310?
CVE-2015-8310 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-8310?
Check the references section above for vendor advisories and patch information. Affected products include: Fomori Cherrymusic.