Description


A vulnerability has been found in code-projects Online Music Site 1.0. This affects an unknown function of the file /Frontend/AlbumByCategory.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

Related CPE's


References



https://github.com/Limingqian123/CVE/issues/16

ExploitIssue TrackingThird Party Advisory

https://vuldb.com/?ctiid.339381

Permissions RequiredVDB Entry

https://vuldb.com/?id.339381

Third Party AdvisoryVDB Entry

https://vuldb.com/?submit.729252

Third Party AdvisoryVDB Entry

https://github.com/Limingqian123/CVE/issues/16

ExploitIssue TrackingThird Party Advisory

Weaknesses



CWE-74CWE-89


CWE-89

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

7.3 · High

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2026-01-02T19:15:47.260Z

2 weeks ago

Last modified

2026-01-09T22:06:05.507Z

1 week ago