Security Advisory
CVE-2021-47915
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
PHP Melody version 3.0 contains a remote SQL injection vulnerability in the video edit module that allows authenticated attackers to inject malicious SQL commands. Attackers can exploit the unvalidated vid parameter to execute arbitrary database queries and potentially compromise the web application and database management system.