📦 Music Management System

by Lopalopa

🔍 What is Music Management System?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-42781

CRITICAL CVSS 9.8 Aug 21, 2024

A SQL injection vulnerability in Kashipara Music Management System v1.0 allows remote attackers to bypass authentication and execute arbitrary SQL commands via the email parameter in the login endpoin...

CVE-2024-42783

CRITICAL CVSS 9.8 Aug 21, 2024

Kashipara Music Management System v1.0 contains a SQL injection vulnerability in the manage_playlist_items.php endpoint via the 'pid' parameter. Attackers can execute arbitrary SQL commands to steal, ...

CVE-2024-42777

CRITICAL CVSS 9.8 Aug 21, 2024

An unrestricted file upload vulnerability in Kashipara Music Management System v1.0 allows attackers to upload malicious PHP files through the signup functionality. This enables remote code execution ...

CVE-2024-42798

HIGH CVSS 7.6 Sep 16, 2024

An incorrect access control vulnerability in Kashipara Music Management System v1.0 allows low-privileged attackers to access administrator functions and take over admin accounts. This affects all use...

CVE-2024-42793

HIGH CVSS 8.0 Aug 28, 2024

A Cross-Site Request Forgery (CSRF) vulnerability in Kashipara Music Management System v1.0 allows attackers to trick authenticated users into performing unauthorized actions, such as modifying user a...

CVE-2024-42779

HIGH CVSS 8.8 Aug 21, 2024

An unrestricted file upload vulnerability in Kashipara Music Management System v1.0 allows attackers to upload malicious PHP files via the /music/ajax.php endpoint. This enables remote code execution ...

CVE-2024-42785

HIGH CVSS 8.8 Aug 21, 2024

A SQL injection vulnerability in Kashipara Music Management System v1.0 allows attackers to execute arbitrary SQL commands via the 'id' parameter in the view_playlist page. This could lead to unauthor...

CVE-2024-42794

MEDIUM CVSS 4.7 Sep 16, 2024

Kashipara Music Management System v1.0 has an incorrect access control vulnerability in the /music/ajax.php endpoint that allows unauthorized users to modify user accounts. This enables attackers to p...

CVE-2024-42796

MEDIUM CVSS 5.9 Sep 16, 2024

An unauthenticated attacker can delete music genre entries in Kashipara Music Management System v1.0 via the /music/ajax.php?action=delete_genre endpoint. This vulnerability affects all deployments of...

CVE-2024-42789

MEDIUM CVSS 6.3 Aug 26, 2024

A reflected cross-site scripting (XSS) vulnerability in Kashipara Music Management System v1.0 allows remote attackers to inject malicious scripts via the 'page' parameter in /music/controller.php. Th...