CVE-2026-15540

A vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is an unknown function of the file /admin/index.php of the component Administrative Interface. Performing a manipulation of the argument page results in improper control of filename for include/require statement in php program. It is possible to initiate the attack remotely. The exploit is now public and may be used.
Configurations

No configuration.

History

13 Jul 2026, 08:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-13 08:16

Updated : 2026-07-13 19:17


NVD link : CVE-2026-15540

Mitre link : CVE-2026-15540

CVE.ORG link : CVE-2026-15540


JSON object : View

Products Affected

No product.

CWE
CWE-73

External Control of File Name or Path

CWE-98

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')