PT-2026-6957 · Code Projects · Online Music Site

·

CVE-2026-2133

·

Published

2026-02-08

·

Updated

2026-02-13

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions code-projects Online Music Site version 1.0
Description A flaw exists in code-projects Online Music Site that allows for unrestricted file uploads. This is due to manipulation of the txtimage argument within an unknown function of the file '/Administrator/PHP/AdminUpdateCategory.php'. The attack can be carried out remotely. The exploit for this issue has been publicly released and may be used in attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-2133

Affected Products

Online Music Site