Impact
The vulnerability exists in an unidentified function of AdminAddCategory.php in Online Music Site 1.0, permitting an attacker to inject arbitrary SQL statements. Successful exploitation could allow the attacker to read, modify, or delete data stored in the application database, thereby compromising the confidentiality and integrity of the platform's data. The CVE describes this flaw as a SQL injection that can be triggered remotely.
Affected Systems
The affected product is code‑projects Online Music Site version 1.0, with the vulnerability located in the /Administrator/PHP/AdminAddCategory.php file of the administration module. Administrators accessing this script over the web are potentially exposed to the risk.
Risk and Exploitability
The CVSS v3.1 score of 5.1 indicates moderate risk, while the EPSS score of <1% shows the flaw is rarely exploited at present. It is not included in the CISA KEV catalog. The attack can be performed remotely, as the flaw resides in a publicly reachable administrative page. Given these metrics, the vulnerability represents a non‑critical but still meaningful threat that should be addressed promptly.
OpenCVE Enrichment