PHP Melody 3.0 contains a persistent cross-site scripting vulnerability in the video editor that allows privileged users to inject malicious scripts. Attackers can exploit the WYSIWYG editor to execute persistent scripts, potentially leading to session hijacking and application manipulation.
References
Configurations
No configuration.
History
03 Feb 2026, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.vulnerability-lab.com/get_content.php?id=2291 - |
Information
Published : 2026-02-01 13:15
Updated : 2026-02-03 17:15
NVD link : CVE-2021-47913
Mitre link : CVE-2021-47913
CVE.ORG link : CVE-2021-47913
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
