Description
A security vulnerability has been detected in code-projects Online Music Site 1.0. Affected by this vulnerability is an unknown functionality of the file /login.php. Such manipulation of the argument username/password leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
Published: 2026-01-05
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the login.php script of code-projects Online Music Site 1.0, where manipulating the username and password fields allows an attacker to inject arbitrary SQL statements. This flaw can enable unauthorized data access, modification, or deletion in the underlying database. The vulnerability is reported as exploitable remotely, meaning an attacker can trigger the injection without needing credential or local access.

Affected Systems

The affected product is code-projects’ Online Music Site version 1.0. No other versions or components are explicitly identified as vulnerable. The issue is specific to the login functionality on this platform.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate risk, and the EPSS score of less than 1% suggests low current exploitation likelihood. Although the vulnerability is not listed in CISA’s KEV catalog, the remote nature of the attack vector means an attacker could readily craft a malicious payload to exploit the site, potentially leading to unauthorized data exposure or compromise of the database.

Generated by OpenCVE AI on April 18, 2026 at 08:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor's latest security patch or upgrade to the newest version of the Online Music Site to address the login.php injection flaw.
  • If an immediate patch is unavailable, implement input validation by ensuring that the username and password fields use parameterized queries or proper escaping to prevent SQL injection.
  • Continuously monitor authentication logs for abnormal login attempts and enforce IP blocking or rate limiting to mitigate brute-force or exploitation attempts.

Generated by OpenCVE AI on April 18, 2026 at 08:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 23 Feb 2026 08:30:00 +0000

Type Values Removed Values Added
References

Mon, 12 Jan 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Fabian
Fabian online Music Site
CPEs cpe:2.3:a:fabian:online_music_site:1.0:*:*:*:*:*:*:*
Vendors & Products Fabian
Fabian online Music Site

Tue, 06 Jan 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Code-projects
Code-projects online Music Site
Vendors & Products Code-projects
Code-projects online Music Site

Tue, 06 Jan 2026 00:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Jan 2026 20:45:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in code-projects Online Music Site 1.0. Affected by this vulnerability is an unknown functionality of the file /login.php. Such manipulation of the argument username/password leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
Title code-projects Online Music Site login.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Code-projects Online Music Site
Fabian Online Music Site
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-23T08:20:05.077Z

Reserved: 2026-01-05T15:00:28.755Z

Link: CVE-2026-0605

cve-icon Vulnrichment

Updated: 2026-01-05T21:08:29.456Z

cve-icon NVD

Status : Modified

Published: 2026-01-05T21:16:14.360

Modified: 2026-02-23T09:16:35.130

Link: CVE-2026-0605

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T08:30:35Z

Weaknesses