Impact
The vulnerability lies in an unvalidated argument called ID within the ViewSongs.php file of the code-projects Online Music Site 1.0. This flaw allows attackers to inject arbitrary SQL statements, compromising the integrity and confidentiality of the underlying database. The weakness is a classic injection flaw, as identified by CWE-89.
Affected Systems
Vendors code-projects:Online Music Site run the affected product version 1.0 on their web servers. Only this specific version is confirmed to be vulnerable.
Risk and Exploitability
With a CVSS score of 6.9 the vulnerability is classified as medium severity. The EPSS score of less than 1% indicates a low probability of exploitation in the wild, and the KEV catalog does not list this CVE, so no confirmed large‑scale attacks are reported. The likely attack vector is remote, contacting the web application with a crafted ID parameter via the browser or automated scripts. An attacker who succeeds could read, modify, or delete database records, and potentially pivot to other systems if credentials are stored in the same database.
OpenCVE Enrichment