CVE-2026-19230: SourceCodester Photo Share Website Comment Input Box ajax.php save_upload cross site scripting
A vulnerability was identified in SourceCodester Photo Share Website 1.0. This affects an unknown part of the file /social/ajax.php?action=saveupload of the component Comment Input Box. The manipulation of the argument content leads to cross site scripting. The attack may be initiated remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19230?
The severity of CVE-2026-19230 is classified as low with a score of 3.5.
How do I fix CVE-2026-19230?
To fix CVE-2026-19230, sanitize and validate the input in the comment input box to prevent cross site scripting.
What component is affected by CVE-2026-19230?
CVE-2026-19230 affects the Comment Input Box of the SourceCodester Photo Share Website.
What type of vulnerability is CVE-2026-19230?
CVE-2026-19230 is a cross site scripting (XSS) vulnerability.
Can CVE-2026-19230 be exploited remotely?
Yes, CVE-2026-19230 can be exploited remotely due to the nature of the input handling in the affected component.