Impact
The flaw resides in the AdminEditCategory.php page of code‑projects Online Music Site 1.0. An attacker can manipulate the ID parameter sent to the script, which is included directly in an SQL query without proper sanitization. This permits arbitrary SQL commands to be executed on the database, enabling data exfiltration, modification, or deletion. The weakness is identified as CWE‑74 and CWE‑89.
Affected Systems
Affected systems are deployments of the code‑projects Online Music Site 1.0. The vulnerability exists in the Administrator/PHP/AdminEditCategory.php file of this version. Only installations running this exact release are at risk; newer or patched versions may no longer contain the flaw.
Risk and Exploitability
The CVSS base score is 6.9, indicating a moderate severity impact on confidentiality and integrity. The EPSS score is below 1%, suggesting a low probability of exploitation in the wild, yet the vulnerability is publicly available and can be triggered from a remote location. No CVE is listed in the CISA KEV catalogue, implying limited known exploitation, but the potential for damage remains if an attacker gains administrative access.
OpenCVE Enrichment