PT-2026-6957 · Code Projects · Online Music Site

M202372062

·

Published

2026-02-08

·

Updated

2026-02-13

·

CVE-2026-2133

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions code-projects Online Music Site version 1.0
Description A flaw exists in code-projects Online Music Site that allows for unrestricted file uploads. This is due to manipulation of the txtimage argument within an unknown function of the file '/Administrator/PHP/AdminUpdateCategory.php'. The attack can be carried out remotely. The exploit for this issue has been publicly released and may be used in attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2026-2133

Affected Products

Online Music Site