CVE-2026-19196: SourceCodester Photo Share Website ajax.php login sql injection
Published Aug 7, 2026
·Updated
A vulnerability was found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of the file /social/ajax.php?action=login. The manipulation of the argument email results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.
Affected Software
1 affected component
Sourcecodester Photo Share Website=1.0
Event History
Aug 7, 2026
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-19196?
The severity of CVE-2026-19196 is classified as high with a score of 7.3.
2
What types of attacks can exploit CVE-2026-19196?
CVE-2026-19196 can be exploited through remote SQL injection attacks via the email argument.
3
How do I fix CVE-2026-19196?
To mitigate CVE-2026-19196, ensure that proper input validation and prepared statements are implemented for the login function.
4
What software is affected by CVE-2026-19196?
CVE-2026-19196 affects Version 1.0 of the SourceCodester Photo Share Website.
5
When was CVE-2026-19196 published?
CVE-2026-19196 was published on August 7, 2026.