Executive brief
Online Music Site, a web application for managing music libraries, contains a security flaw in its administrative album deletion component. An attacker can exploit this to gain unauthorized access to the underlying database without needing a login. This could lead to the theft of sensitive user information, modification of site content, or a complete takeover of the application's data.
Technical details
A SQL injection vulnerability exists in code-projects Online Music Site 1.0 within the /Administrator/PHP/AdminDeleteAlbum.php file. The application fails to properly sanitize or validate the 'id' GET parameter before using it in a database query. A remote, unauthenticated attacker can provide a malicious payload (such as time-based blind SQL injection) to execute arbitrary SQL commands. This allows for unauthorized data extraction, modification, or deletion. A public exploit (PoC) using sqlmap has been disclosed. No official patch is currently available; developers are advised to implement prepared statements and parameter binding.
Affected products
- code-projects Online Music Site 1.0
Timeline
- 2026-05-21: disclosed: Vulnerability details and PoC shared on GitHub.
- 2026-06-08: advisory: CVE-2026-11489 published.