CVE-2026-3070: SourceCodester Modern Image Gallery App upload.php cross site scripting
A vulnerability was detected in SourceCodester Modern Image Gallery App 1.0. Affected by this vulnerability is an unknown functionality of the file upload.php. The manipulation of the argument filename results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3070?
CVE-2026-3070 has a moderate severity level due to its potential for cross-site scripting attacks.
How do I fix CVE-2026-3070?
To fix CVE-2026-3070, ensure proper input validation and sanitization for the filename argument in the upload.php file.
What is the impact of CVE-2026-3070?
The impact of CVE-2026-3070 allows attackers to execute arbitrary scripts in the context of a user's browser.
Who is affected by CVE-2026-3070?
CVE-2026-3070 affects users of SourceCodester Modern Image Gallery App version 1.0 who utilize the upload.php functionality.
Is CVE-2026-3070 exploitable remotely?
Yes, CVE-2026-3070 can be exploited remotely by sending crafted requests to the upload.php file.