PT-2026-5559 · Unknown · Php Melody
Published
2026-02-01
·
Updated
2026-02-01
·
CVE-2021-47914
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
PHP Melody version 3.0
Description
PHP Melody version 3.0 has a persistent cross-site scripting issue in the
edit-video.php file’s submitted parameter. This allows attackers to inject malicious script code. Successful exploitation could lead to the execution of arbitrary JavaScript, potentially resulting in session hijacking, persistent phishing, and manipulation of application modules.Recommendations
Update PHP Melody to a newer version that addresses this vulnerability. As a temporary workaround, sanitize all input to the
submitted parameter in the edit-video.php file.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Php Melody