PT-2026-2042 · Code Projects · Online Music Site

Yeliuyun

·

Published

2026-01-12

·

Updated

2026-01-12

·

CVE-2026-0852

CVSS v2.0
7.5
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions code-projects Online Music Site version 1.0
Description A security flaw exists in code-projects Online Music Site 1.0. The issue involves a SQL injection impacting an unknown function within the file
/Administrator/PHP/AdminUpdateUser.php
. Manipulation of the
ID
argument allows for remote execution of the attack. The exploit has been publicly released and may be used for attacks.
Recommendations Restrict or disable access to the file
/Administrator/PHP/AdminUpdateUser.php
as a temporary measure. Avoid using the
ID
parameter in the
/Administrator/PHP/AdminUpdateUser.php
file until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-0852

Affected Products

Online Music Site