PHP Melody Multiple Vulnerabilities

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Vulnerabilities Summary The following advisory describes three (3) vulnerabilities found in PHP Melody version 2.7.3. PHP Melody is a “self-hosted Video CMS which evolved over the last 9 years. SEO optimization, unbeaten security and speed are advantages you no longer have to compromise on. A truly great CMS should help you save time and make your life easier not complicate it. Nobody enjoys spending time and money on inferior solutions. If you value your time, don’t settle for anything but the best video CMS with a proven track record, constant support and updates.” The vulnerabilities found in PHP Melody are: * Stored PreAuth XSS that leads to administrator account takeover * SQL Injection (1) * SQL Injection (2) ### Credit An independent security researcher, Paulos Yibelo, has reported this vulnerability to Beyond Security’s SecuriTeam Secure Disclosure program. ### Vendor response PHP Melody has released patches to address this vulnerability. For more information:...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息