PT-2026-69066 · Sourcecodester · Photo Share Website
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SourceCodester Photo Share Website version 1.0
Description
An unrestricted upload issue exists in the
/social/ajax.php?action=save upload endpoint. Remote attackers can exploit this by manipulating the img[] and imgName[] variables, allowing the upload of unauthorized files to the server.Recommendations
Update SourceCodester Photo Share Website version 1.0 to a patched version.
Restrict access to the
/social/ajax.php?action=save upload endpoint to minimize the risk of exploitation.Exploit
Fix
Unrestricted File Upload
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Photo Share Website