PT-2026-47252 · Unknown · Online Music Site
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Online Music Site version 1.0
Description
An issue exists in the processing of the '/Frontend/Search.php' endpoint. Manipulation of the
Category argument allows for SQL injection, which is a technique used to execute malicious SQL statements that control a database server. This attack can be initiated remotely.Recommendations
Update Online Music Site version 1.0 to a newer version that contains a fix. As a temporary workaround, restrict access to the '/Frontend/Search.php' endpoint or avoid using the
Category parameter until the issue is resolved.Exploit
Fix
SQL injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Online Music Site