CVE-2026-0607: code-projects Online Music Site AdminViewSongs.php sql injection
A flaw has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PHP/AdminViewSongs.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0607?
CVE-2026-0607 has a high severity rating due to its potential to allow remote SQL injection attacks.
How do I fix CVE-2026-0607?
To fix CVE-2026-0607, sanitize and validate input parameters in the /Administrator/PHP/AdminViewSongs.php file to prevent SQL injection.
What systems are affected by CVE-2026-0607?
CVE-2026-0607 affects version 1.0 of the Code-projects Online Music Site application.
Can CVE-2026-0607 be exploited remotely?
Yes, CVE-2026-0607 can be exploited remotely if the vulnerability is present in the system.
What are the consequences of exploiting CVE-2026-0607?
Exploiting CVE-2026-0607 can lead to unauthorized access and manipulation of the database through SQL injection.