Impact
The flaw allows an attacker to inject arbitrary SQL statements by manipulating the ID argument in the AdminUpdateUser.php file. This can lead to unauthorized reading, alteration, or deletion of database records and may be used to elevate privileges within the application, compromising the confidentiality and integrity of the stored music data.
Affected Systems
The vulnerability affects the code-projects Online Music Site version 1.0. No other vendors or product versions are listed.
Risk and Exploitability
With a CVSS score of 6.9 the weakness is considered moderate to high severity. The EPSS score of less than 1% indicates a low probability of exploitation at this time, and the issue is not listed in the CISA KEV catalog. However, the public release of an exploit and remote execution capability means an attacker can reach the vulnerable component over the network and exploit the injection without authentication.
OpenCVE Enrichment