Home

Description

PHP Melody version 3.0 contains a persistent cross-site scripting vulnerability in the edit-video.php submitted parameter that allows remote attackers to inject malicious script code. Attackers can exploit this vulnerability to execute arbitrary JavaScript, potentially leading to session hijacking, persistent phishing, and manipulation of application modules.

PUBLISHED Reserved 2026-02-01 | Published 2026-02-01 | Updated 2026-02-02 | Assigner VulnCheck




MEDIUM: 5.1CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
MEDIUM: 6.4CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

Problem types

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

Default status
unaffected

3.0
affected

Credits

Vulnerability-Lab [Research Team] finder

References

www.vulnerability-lab.com/get_content.php?id=2292 (Vulnerability Lab Advisory) exploit

www.phpsugar.com/...php-melody-3-0-vulnerability-report-fix/ (Vulnerability Lab Advisory) patch

www.phpsugar.com/phpmelody.html (Product Homepage) product

www.vulncheck.com/...-vulnerability-via-edit-video-parameter (VulnCheck Advisory: PHP Melody 3.0 Persistent XSS Vulnerability via Edit Video Parameter) third-party-advisory

cve.org (CVE-2021-47914)

nvd.nist.gov (CVE-2021-47914)

Download JSON