CVE-2024-42798: Lopalopa Music Management System
High severity, CVSS 7.6. EPSS: 0.4% chance of exploitation in the next 30 days.
An Incorrect Access Control vulnerability was found in /music/index.php?page=user_list and /music/index.php?page=edit_user in Kashipara Music Management System v1.0. This allows a low privileged attacker to take over the administrator account.
Affected products
- Lopalopa Music Management System: version 1.0 only
Published 2024-09-16. Last modified 2026-06-17.