CVE-2024-42798: Lopalopa Music Management System

High severity, CVSS 7.6. EPSS: 0.4% chance of exploitation in the next 30 days.

An Incorrect Access Control vulnerability was found in /music/index.php?page=user_list and /music/index.php?page=edit_user in Kashipara Music Management System v1.0. This allows a low privileged attacker to take over the administrator account.

Affected products

  • Lopalopa Music Management System: version 1.0 only

Published 2024-09-16. Last modified 2026-06-17.