You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This is not secure, as you can just insert your own HTML/js into filename or metadata and have it execute inside the application: e.g. edit any MP3 file and set title to <script>alert('xss')</script>, and the alert box will pop up when you select a folder containing the song.
The text was updated successfully, but these errors were encountered:
This is not secure, as you can just insert your own HTML/js into filename or metadata and have it execute inside the application: e.g. edit any MP3 file and set title to
<script>alert('xss')</script>
, and the alert box will pop up when you select a folder containing the song.The text was updated successfully, but these errors were encountered: