Description
A vulnerability has been found in code-projects Online Music Site 1.0. This affects an unknown function of the file /Frontend/AlbumByCategory.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
References
Product
https://github.com/Limingqian123/CVE/issues/16
ExploitIssue TrackingThird Party Advisory
https://vuldb.com/?ctiid.339381
Permissions RequiredVDB Entry
Third Party AdvisoryVDB Entry
https://vuldb.com/?submit.729252
Third Party AdvisoryVDB Entry
https://github.com/Limingqian123/CVE/issues/16
ExploitIssue TrackingThird Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
7.3 · High
Information
Source identifier
Vulnerability status
Analyzed
Published
2026-01-02T19:15:47.260Z
2 weeks agoLast modified
2026-01-09T22:06:05.507Z
1 week ago