PT-2026-5559 · Unknown · Php Melody
CVE-2021-47914
·
Publicado
2026-02-01
·
Atualizado
2026-02-01
CVSS v3.1
6.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
PHP Melody version 3.0
Description
PHP Melody version 3.0 has a persistent cross-site scripting issue in the
edit-video.php file’s submitted parameter. This allows attackers to inject malicious script code. Successful exploitation could lead to the execution of arbitrary JavaScript, potentially resulting in session hijacking, persistent phishing, and manipulation of application modules.Recommendations
Update PHP Melody to a newer version that addresses this vulnerability. As a temporary workaround, sanitize all input to the
submitted parameter in the edit-video.php file.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Php Melody