Home/Product/lopalopa music management system
Product

lopalopa music management system

22 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-42797
all versions
An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_playlist in Kashipara Music Management System
9.8CRITICAL
CVE-2024-42798
all versions
An Incorrect Access Control vulnerability was found in /music/index.php?page=user_list and /music/index.php?page=edit_user in Kash
7.6HIGH
CVE-2024-42796
all versions
An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_genre in Kashipara Music Management System v1
5.9MEDIUM
CVE-2024-42795
all versions
An Incorrect Access Control vulnerability was found in /music/view_user.php?id=3 and /music/controller.php?page=edit_user&id=3 in
4.2MEDIUM
CVE-2024-42794
all versions
Kashipara Music Management System v1.0 is vulnerable to Incorrect Access Control via /music/ajax.php?action=save_user.
4.7MEDIUM
CVE-2024-42793
all versions
A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via a crafted request to the
8.0HIGH
CVE-2024-42792
all versions
A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via /music/ajax.php?action=d
3.5LOW
CVE-2024-42790
all versions
A Reflected Cross Site Scripting (XSS) vulnerability was found in "/music/index.php?page=test" in Kashipara Music Management Syste
5.4MEDIUM
CVE-2024-42791
all versions
A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via /music/ajax.php?action=d
8.8HIGH
CVE-2024-42788
all versions
A Stored Cross Site Scripting (XSS) vulnerability was found in "/music/ajax.php?action=save_music" in Kashipara Music Management S
6.1MEDIUM
CVE-2024-42789
all versions
A Reflected Cross Site Scripting (XSS) vulnerability was found in "/music/controller.php?page=test" in Kashipara Music Management
6.3MEDIUM
CVE-2024-42787
all versions
A Stored Cross Site Scripting (XSS) vulnerability was found in "/music/ajax.php?action=save_playlist" in Kashipara Music Managemen
6.1MEDIUM
CVE-2024-42786
all versions
A SQL injection vulnerability in "/music/view_user.php" in Kashipara Music Management System v1.0 allows an attacker to execute ar
8.8HIGH
CVE-2024-42785
all versions
A SQL injection vulnerability in /music/index.php?page=view_playlist in Kashipara Music Management System v1.0 allows an attacker
8.8HIGH
CVE-2024-42784
all versions
A SQL injection vulnerability in "/music/controller.php?page=view_music" in Kashipara Music Management System v1.0 allows an attac
9.8CRITICAL
CVE-2024-42783
all versions
Kashipara Music Management System v1.0 is vulnerable to SQL Injection via /music/manage_playlist_items.php. An attacker can execut
9.8CRITICAL
CVE-2024-42782
all versions
A SQL injection vulnerability in "/music/ajax.php?action=find_music" in Kashipara Music Management System v1.0 allows an attacker
9.8CRITICAL
CVE-2024-42781
all versions
A SQL injection vulnerability in "/music/ajax.php?action=login" of Kashipara Music Management System v1.0 allows remote attackers
9.8CRITICAL
CVE-2024-42780
all versions
An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_genre" in Kashipara Music Management System v1
8.8HIGH
CVE-2024-42779
all versions
An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_music" in Kashipara Music Management System v1
8.8HIGH
CVE-2024-42778
all versions
An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_playlist" in Kashipara Music Management System
8.8HIGH
CVE-2024-42777
all versions
An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=signup" of Kashipara Music Management System v1.0,
9.8CRITICAL
threatengine.sh