CVE-2026-10171: code-projects Online Music Site AdminUpdateAlbum.php sql injection
Published May 31, 2026
·Updated
A vulnerability has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PHP/AdminUpdateAlbum.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
Code-projects Online Music Site=1.0
Event History
May 31, 2026
CVE Published
via MITRE·05:45 AM
Data Sourced
via MITRE·05:45 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
Nov 7, 58382
Event
via NVD·01:11 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-10171?
The severity of CVE-2026-10171 is rated as medium with a score of 4.7.
2
How do I fix CVE-2026-10171?
To fix CVE-2026-10171, sanitize and validate all user inputs in the AdminUpdateAlbum.php file to prevent SQL injection.
3
What type of vulnerability is CVE-2026-10171?
CVE-2026-10171 is a SQL injection vulnerability affecting the Online Music Site.
4
Can CVE-2026-10171 be exploited remotely?
Yes, the exploit for CVE-2026-10171 can be launched remotely.
5
What component is affected by CVE-2026-10171?
CVE-2026-10171 affects the AdminUpdateAlbum.php file in the administration panel of the Online Music Site.