VulnerabilityAnalyzed
CVE-2026-2213
The attack may be performed from remote.
LOW 2.0EPSS 0.29%
Does this matter?
Lower severity and a low EPSS score (0.29%). Track it; it rarely justifies an emergency change on its own.
Description
A security flaw has been discovered in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /Administrator/PHP/AdminAddAlbum.php. The manipulation of the argument txtimage results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.
- CVSS 4.0
- 2.0 LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.29% probability · 22th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284, CWE-434
- Affected
- fabian/online music site
- Source
- cna@vuldb.com
References
- https://code-projects.org/Product
- https://github.com/yuji0903/silver-guide/issues/8Exploit, Issue Tracking
- https://vuldb.com/?ctiid.344929Permissions Required, VDB Entry
- https://vuldb.com/?id.344929Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.752601Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.