Description


A security flaw has been discovered in code-projects Online Music Site 1.0. The impacted element is an unknown function of the file /Administrator/PHP/AdminUpdateUser.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

Related CPE's


References




https://vuldb.com/?ctiid.340447

Permissions RequiredVDB Entry

https://vuldb.com/?id.340447

Third Party AdvisoryVDB Entry

https://vuldb.com/?submit.734136

Third Party AdvisoryVDB Entry

Weaknesses



CWE-74CWE-89

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

7.3 · High

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2026-01-12T01:15:49.950Z

3 days ago

Last modified

2026-01-14T22:19:33.933Z

5 hours ago