Description
A vulnerability was determined in code-projects Online Music Site 1.0. This issue affects some unknown processing of the file /Frontend/Search.php. This manipulation of the argument Category causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
Problem types
Product status
Timeline
| 2026-06-07: | Advisory disclosed |
| 2026-06-07: | VulDB entry created |
| 2026-06-07: | VulDB entry last update |
Credits
lixiaobailrl (VulDB User)
References
vuldb.com/vuln/369110 (VDB-369110 | code-projects Online Music Site Search.php sql injection)
vuldb.com/vuln/369110/cti (VDB-369110 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/cve/CVE-2026-11490 (CVE-2026-11490 | CVE Analysis and Report)
vuldb.com/submit/836666 (Submit #836666 | code-projects ONLINE MUSIC SITE V1.0 Code-projects ONLINE MUSIC SITE V1.0 Search.php SQL injection)
github.com/xiaobbai/CVE1/issues/1
code-projects.org/