Threat Intel

v0.1

← CVEs

CVE-2021-47913

MED 6.4
Published
2026-02-01
Last Modified
2026-02-11
Affected Apps
12
Affected Devices
25
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
PHP Melody 3.0 contains a persistent cross-site scripting vulnerability in the video editor that allows privileged users to inject malicious scripts. Attackers can exploit the WYSIWYG editor to execute persistent scripts, potentially leading to session hijacking and application manipulation.
References 5