Description
A security flaw has been discovered in code-projects Online Music Site 1.0. The impacted element is an unknown function of the file /Administrator/PHP/AdminAddCategory.php. The manipulation results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.
Published: 2026-01-28
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection
Action: Patch Now
AI Analysis

Impact

The vulnerability exists in an unidentified function of AdminAddCategory.php in Online Music Site 1.0, permitting an attacker to inject arbitrary SQL statements. Successful exploitation could allow the attacker to read, modify, or delete data stored in the application database, thereby compromising the confidentiality and integrity of the platform's data. The CVE describes this flaw as a SQL injection that can be triggered remotely.

Affected Systems

The affected product is code‑projects Online Music Site version 1.0, with the vulnerability located in the /Administrator/PHP/AdminAddCategory.php file of the administration module. Administrators accessing this script over the web are potentially exposed to the risk.

Risk and Exploitability

The CVSS v3.1 score of 5.1 indicates moderate risk, while the EPSS score of <1% shows the flaw is rarely exploited at present. It is not included in the CISA KEV catalog. The attack can be performed remotely, as the flaw resides in a publicly reachable administrative page. Given these metrics, the vulnerability represents a non‑critical but still meaningful threat that should be addressed promptly.

Generated by OpenCVE AI on April 18, 2026 at 18:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch or upgrade to a newer version of the Online Music Site that contains the fix.
  • Modify the affected AdminAddCategory.php code to use parameterized queries or prepared statements so that all user‑supplied input is properly sanitized and cannot influence the structure of SQL commands.
  • Enforce strict access controls on the administration area, requiring strong authentication and, if possible, limiting access to trusted IP ranges or VPNs to reduce exposure to the vulnerable script.

Generated by OpenCVE AI on April 18, 2026 at 18:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 06 Feb 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Fabian
Fabian online Music Site
CPEs cpe:2.3:a:fabian:online_music_site:1.0:*:*:*:*:*:*:*
Vendors & Products Fabian
Fabian online Music Site

Thu, 29 Jan 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Code-projects
Code-projects online Music Site
Vendors & Products Code-projects
Code-projects online Music Site

Wed, 28 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 28 Jan 2026 21:00:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in code-projects Online Music Site 1.0. The impacted element is an unknown function of the file /Administrator/PHP/AdminAddCategory.php. The manipulation results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.
Title code-projects Online Music Site AdminAddCategory.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Code-projects Online Music Site
Fabian Online Music Site
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-23T09:00:58.745Z

Reserved: 2026-01-28T13:41:01.286Z

Link: CVE-2026-1533

cve-icon Vulnrichment

Updated: 2026-01-28T21:38:39.425Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-28T21:16:10.927

Modified: 2026-02-06T18:37:07.867

Link: CVE-2026-1533

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T18:45:05Z

Weaknesses