CVE-2023-0963

HIGH

SourceCodester Music Gallery Site 1.0 - Improper Access Control in Users.php POST Request Handler

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-0963. PoCs published by Muhammad Navaid Zafar Ansari.

AI-analyzed exploit summary This exploit demonstrates a broken access control vulnerability in Music Gallery Site v1.0, allowing unauthenticated users to create admin accounts via a POST request to Users.php. The vulnerability arises from missing authentication checks in Users.php and Master.php.

Description

A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been rated as critical. This issue affects some unknown processing of the file Users.php of the component POST Request Handler. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-221633 was assigned to this vulnerability.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Muhammad Navaid Zafar Ansari · textwebappsphp
https://www.exploit-db.com/exploits/51289

This exploit demonstrates a broken access control vulnerability in Music Gallery Site v1.0, allowing unauthenticated users to create admin accounts via a POST request to Users.php. The vulnerability arises from missing authentication checks in Users.php and Master.php.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Music Gallery Site v1.0
No auth needed
Prerequisites: Network access to the target application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
https://vuldb.com/?id.221633
Permissions Required, Third Party Advisory, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.221633

Scores

CVSS v3 7.3
EPSS 0.0467
EPSS Percentile 90.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (1)
music_gallery_site_project/music_gallery_site 1.0
Published Feb 22, 2023
Tracked Since Feb 18, 2026