CVE-2026-2133: code-projects Online Music Site AdminUpdateCategory.php unrestricted upload
A weakness has been identified in code-projects Online Music Site 1.0. Impacted is an unknown function of the file /Administrator/PHP/AdminUpdateCategory.php. This manipulation of the argument txtimage causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2133?
CVE-2026-2133 is classified as a high severity vulnerability due to the potential for unrestricted file upload.
How do I fix CVE-2026-2133?
To mitigate CVE-2026-2133, implement strict file validation and allow only certain file types to be uploaded.
What is affected by CVE-2026-2133?
CVE-2026-2133 affects the AdminUpdateCategory.php file in the code-projects Online Music Site.
What kind of attacks can CVE-2026-2133 lead to?
CVE-2026-2133 can lead to remote code execution if an attacker uploads malicious files to the server.
Is there a patch available for CVE-2026-2133?
As of now, there is no official patch available for CVE-2026-2133; users should apply recommended workarounds.