Junglewise Threat Intelligence

CVE-2026-13567: Code-projects Online Music Site stored XSS in Feedback.php

CVE-2026-13567 · Severity: medium · CVSS 4.3 · Published 2026-06-29

Technologies: Code-Projects Online Music Site. Vendors: Code-Projects.

Executive brief

A security vulnerability exists in the Online Music Site 1.0 software, which is used to manage and host music content. An attacker can submit malicious scripts through the site's feedback form, which are then permanently stored on the server. When an administrator or another user views this feedback, the script executes in their browser, potentially allowing the attacker to steal login sessions, hijack accounts, or redirect users to malicious websites.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in Code-projects Online Music Site 1.0 within the /Frontend/Feedback.php file. The application fails to sanitize or escape user-supplied input in the 'fname', 'femail', 'faddress', and 'fmessage' POST parameters before storing them in the 'tblfeedback' database table. Because these values are later rendered in an HTML context without proper output encoding, a remote, unauthenticated attacker can execute arbitrary JavaScript in the context of a victim's browser. This can lead to session hijacking via cookie theft or unauthorized actions performed on behalf of the victim. No patch is currently reported for this open-source project.

Affected products

  • Code-projects Online Music Site 1.0

Timeline

  • 2026-05-31: disclosed: Vulnerability reported on GitHub by qwessec
  • 2026-06-29: advisory: CVE published to NVD

References

Related threats