← Back

Music Management System

music_management_system

Vendor: Lopalopa • 22 CVEs

CVEs (22)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lopalopa
1Music Management System
Apr 28, 2025
Sep 25, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_playlist in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to delete the valid music pla...Show more
An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_playlist in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to delete the valid music playlist entries.Show less
1Lopalopa
1Music Management System
Apr 28, 2025
Sep 16, 2024
N/A· v4
7.6 HIGH· v3
N/A· v2
An Incorrect Access Control vulnerability was found in /music/index.php?page=user_list and /music/index.php?page=edit_user in Kashipara Music Management System v1.0. This allows a low privileged attacker to take over the...Show more
An Incorrect Access Control vulnerability was found in /music/index.php?page=user_list and /music/index.php?page=edit_user in Kashipara Music Management System v1.0. This allows a low privileged attacker to take over the administrator account.Show less
1Lopalopa
1Music Management System
Apr 28, 2025
Sep 16, 2024
N/A· v4
5.9 MEDIUM· v3
N/A· v2
An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_genre in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to delete the valid music genre...Show more
An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_genre in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to delete the valid music genre entries.Show less
1Lopalopa
1Music Management System
Apr 28, 2025
Sep 16, 2024
N/A· v4
4.2 MEDIUM· v3
N/A· v2
An Incorrect Access Control vulnerability was found in /music/view_user.php?id=3 and /music/controller.php?page=edit_user&id=3 in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attac...Show more
An Incorrect Access Control vulnerability was found in /music/view_user.php?id=3 and /music/controller.php?page=edit_user&id=3 in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to view valid user details.Show less
1Lopalopa
1Music Management System
Apr 28, 2025
Sep 16, 2024
N/A· v4
4.7 MEDIUM· v3
N/A· v2
Kashipara Music Management System v1.0 is vulnerable to Incorrect Access Control via /music/ajax.php?action=save_user.
1Lopalopa
1Music Management System
Aug 30, 2024
Aug 28, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via a crafted request to the /music/ajax.php?action=save_user page.
1Lopalopa
1Music Management System
Sep 5, 2024
Aug 26, 2024
N/A· v4
3.5 LOW· v3
N/A· v2
A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via /music/ajax.php?action=delete_playlist page.
1Lopalopa
1Music Management System
Sep 5, 2024
Aug 26, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A Reflected Cross Site Scripting (XSS) vulnerability was found in "/music/index.php?page=test" in Kashipara Music Management System v1.0. This vulnerability allows remote attackers to execute arbitrary code via the "page...Show more
A Reflected Cross Site Scripting (XSS) vulnerability was found in "/music/index.php?page=test" in Kashipara Music Management System v1.0. This vulnerability allows remote attackers to execute arbitrary code via the "page" parameter.Show less
1Lopalopa
1Music Management System
May 6, 2025
Aug 26, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via /music/ajax.php?action=delete_genre.
1Lopalopa
1Music Management System
May 6, 2025
Aug 26, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A Stored Cross Site Scripting (XSS) vulnerability was found in "/music/ajax.php?action=save_music" in Kashipara Music Management System v1.0. This vulnerability allows remote attackers to execute arbitrary code via "titl...Show more
A Stored Cross Site Scripting (XSS) vulnerability was found in "/music/ajax.php?action=save_music" in Kashipara Music Management System v1.0. This vulnerability allows remote attackers to execute arbitrary code via "title" & "artist" parameter fields.Show less
1Lopalopa
1Music Management System
May 6, 2025
Aug 26, 2024
N/A· v4
6.3 MEDIUM· v3
N/A· v2
A Reflected Cross Site Scripting (XSS) vulnerability was found in "/music/controller.php?page=test" in Kashipara Music Management System v1.0. This vulnerability allows remote attackers to execute arbitrary code via the...Show more
A Reflected Cross Site Scripting (XSS) vulnerability was found in "/music/controller.php?page=test" in Kashipara Music Management System v1.0. This vulnerability allows remote attackers to execute arbitrary code via the "page" parameter.Show less
1Lopalopa
1Music Management System
May 6, 2025
Aug 26, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A Stored Cross Site Scripting (XSS) vulnerability was found in "/music/ajax.php?action=save_playlist" in Kashipara Music Management System v1.0. This vulnerability allows remote attackers to execute arbitrary code via "t...Show more
A Stored Cross Site Scripting (XSS) vulnerability was found in "/music/ajax.php?action=save_playlist" in Kashipara Music Management System v1.0. This vulnerability allows remote attackers to execute arbitrary code via "title" & "description" parameter fields.Show less
1Lopalopa
1Music Management System
Aug 26, 2024
Aug 21, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
A SQL injection vulnerability in "/music/view_user.php" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter of View User Profile Page.
1Lopalopa
1Music Management System
Aug 26, 2024
Aug 21, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
A SQL injection vulnerability in /music/index.php?page=view_playlist in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter.
1Lopalopa
1Music Management System
Aug 26, 2024
Aug 21, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A SQL injection vulnerability in "/music/controller.php?page=view_music" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter.
1Lopalopa
1Music Management System
Sep 6, 2024
Aug 21, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Kashipara Music Management System v1.0 is vulnerable to SQL Injection via /music/manage_playlist_items.php. An attacker can execute arbitrary SQL commands via the "pid" parameter.
1Lopalopa
1Music Management System
Aug 23, 2024
Aug 21, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A SQL injection vulnerability in "/music/ajax.php?action=find_music" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "search" parameter.
1Lopalopa
1Music Management System
Aug 23, 2024
Aug 21, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A SQL injection vulnerability in "/music/ajax.php?action=login" of Kashipara Music Management System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the email parameter.
1Lopalopa
1Music Management System
Aug 23, 2024
Aug 21, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_genre" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a crafted PHP file.
1Lopalopa
1Music Management System
Aug 23, 2024
Aug 21, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_music" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a crafted PHP file.