PT-2026-57644 · Sourcecodester · Online Book Store System
CVE-2026-15539
·
Published
2026-07-13
·
Updated
2026-07-13
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:L/Au:M/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SourceCodester Online Book Store System version 1.0
Description
An unrestricted file upload flaw exists in the Book Image Upload Feature within the
/admin/index.php?page=books endpoint. This issue allows a remote attacker to upload arbitrary files, which can lead to remote code execution (RCE), a state where an attacker can execute malicious commands on the server.Recommendations
Restrict access to the
/admin/index.php?page=books endpoint to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
RCE
Unrestricted File Upload
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Online Book Store System