Junglewise Threat Intelligence

CVE-2026-11489: code-projects Online Music Site SQL injection in AdminDeleteAlbum.php

CVE-2026-11489 · Severity: high · CVSS 7.3 · Published 2026-06-08

Technologies: Code-Projects Online Music Site. Vendors: Code-Projects.

Executive brief

Online Music Site, a web application for managing music libraries, contains a security flaw in its administrative album deletion component. An attacker can exploit this to gain unauthorized access to the underlying database without needing a login. This could lead to the theft of sensitive user information, modification of site content, or a complete takeover of the application's data.

Technical details

A SQL injection vulnerability exists in code-projects Online Music Site 1.0 within the /Administrator/PHP/AdminDeleteAlbum.php file. The application fails to properly sanitize or validate the 'id' GET parameter before using it in a database query. A remote, unauthenticated attacker can provide a malicious payload (such as time-based blind SQL injection) to execute arbitrary SQL commands. This allows for unauthorized data extraction, modification, or deletion. A public exploit (PoC) using sqlmap has been disclosed. No official patch is currently available; developers are advised to implement prepared statements and parameter binding.

Affected products

  • code-projects Online Music Site 1.0

Timeline

  • 2026-05-21: disclosed: Vulnerability details and PoC shared on GitHub.
  • 2026-06-08: advisory: CVE-2026-11489 published.

References

Related threats