Security Advisory

CVE-2021-47915

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-02-01 12:15:49
Last updated 2026-03-05 01:29:17
Assigner VulnCheck
State PUBLISHED

Description

PHP Melody version 3.0 contains a remote SQL injection vulnerability in the video edit module that allows authenticated attackers to inject malicious SQL commands. Attackers can exploit the unvalidated vid parameter to execute arbitrary database queries and potentially compromise the web application and database management system.