CVE-2026-15540: SourceCodester Online Book Store System Administrative index.php php file inclusion
A vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is an unknown function of the file /admin/index.php of the component Administrative Interface. Performing a manipulation of the argument page results in improper control of filename for include/require statement in php program. It is possible to initiate the attack remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15540?
The severity of CVE-2026-15540 is medium with a CVSS score of 4.3.
How do I fix CVE-2026-15540?
To fix CVE-2026-15540, ensure proper validation and sanitization of the 'page' parameter in the /admin/index.php file.
What is CVE-2026-15540 about?
CVE-2026-15540 involves improper control of filename for include/require operations in the SourceCodester Online Book Store System administrative interface.
Who is affected by CVE-2026-15540?
Users of SourceCodester Online Book Store System version 1.0 are affected by CVE-2026-15540.
When was CVE-2026-15540 published?
CVE-2026-15540 was published on July 13, 2026.