CVE-2026-2213: code-projects Online Music Site AdminAddAlbum.php unrestricted upload
A security flaw has been discovered in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /Administrator/PHP/AdminAddAlbum.php. The manipulation of the argument txtimage results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2213?
CVE-2026-2213 is considered a high-severity vulnerability due to its unrestricted file upload functionality.
How do I fix CVE-2026-2213?
To fix CVE-2026-2213, implement file type validation and restrict the types of files that can be uploaded in the AdminAddAlbum.php script.
What is the impact of CVE-2026-2213 on my system?
CVE-2026-2213 can allow an attacker to upload malicious files, leading to potential remote code execution and data breaches.
Which software is affected by CVE-2026-2213?
CVE-2026-2213 affects the code-projects Online Music Site version 1.0.
Can CVE-2026-2213 be exploited remotely?
Yes, CVE-2026-2213 can be exploited remotely by an attacker to upload unauthorized files.