Description
A flaw has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PHP/AdminUpdateAlbum.php. This manipulation of the argument txtimage causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been published and may be used.
Problem types
Product status
Timeline
| 2026-04-27: | Advisory disclosed |
| 2026-04-27: | VulDB entry created |
| 2026-04-27: | VulDB entry last update |
Credits
the_better_you (VulDB User)
References
vuldb.com/vuln/359846 (VDB-359846 | code-projects Online Music Site AdminUpdateAlbum.php unrestricted upload)
vuldb.com/vuln/359846/cti (VDB-359846 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/802840 (Submit #802840 | Code-projects ONLINE MUSIC SITE v1.0 Arbitrary file upload vulnerability)
github.com/gtxy114514/CVE/issues/4
code-projects.org/