CVE-2018-5211: Phpsugar PHP Melody
Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.
PHP Melody version 2.7.1 suffer from SQL Injection Time-based attack on the page ajax.php with the parameter playlist.
Affected products
- Phpsugar PHP Melody: version 2.7.1 only
Published 2018-01-09. Last modified 2026-06-17.