VendorsPHPSUGARphp_melodyany version
Vulnerabilities

PHPSUGAR PHP Melody any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2017-15579
In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via an aa_pages_per_page cookie in a playlist action to watch.php.
Published 2017-10-18 · Modified
9.81 PoCEPSS 0.015
CVE-2017-15578
In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via the image parameter to admin/edit_category.php.
Published 2017-10-18 · Modified
8.81 PoCEPSS 0.013
CVE-2017-15648
In PHPSUGAR PHP Melody before 2.7.3, page_manager.php has XSS via the page_title parameter.
Published 2017-10-19 · Modified
6.1EPSS 0.007