CVE-2026-0570: code-projects Online Music Site Feedback.php sql injection
A vulnerability was found in code-projects Online Music Site 1.0. This impacts an unknown function of the file /Frontend/Feedback.php. Performing a manipulation of the argument fname results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0570?
CVE-2026-0570 is classified as a high severity vulnerability due to the potential for SQL injection attacks.
How do I fix CVE-2026-0570?
To fix CVE-2026-0570, validate and sanitize inputs for the fname parameter in the Feedback.php file to prevent SQL injection.
Which versions of Online Music Site are affected by CVE-2026-0570?
CVE-2026-0570 affects version 1.0 of code-projects Online Music Site.
Can CVE-2026-0570 be exploited remotely?
Yes, CVE-2026-0570 can be exploited remotely, allowing attackers to execute SQL injection attacks from outside the network.
What part of the Online Music Site is vulnerable in CVE-2026-0570?
The vulnerability in CVE-2026-0570 is located in the /Frontend/Feedback.php file specifically affecting the argument fname.