Vulnerabilities > Fomori
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-03-27 | CVE-2015-8310 | Cross-site Scripting vulnerability in Fomori Cherrymusic Cross-site scripting (XSS) vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to inject arbitrary web script or HTML via the playlistname field when creating a new playlist. | 3.5 |
2017-03-27 | CVE-2015-8309 | Path Traversal vulnerability in Fomori Cherrymusic Directory traversal vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to read arbitrary files via the "value" parameter to "download." | 4.0 |