Security Advisory

CVE-2026-15540

4.3
MEDIUM

Vulnerability Description

A vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is an unknown function of the file /admin/index.php of the component Administrative Interface. Performing a manipulation of the argument page results in improper control of filename for include/require statement in php program. It is possible to initiate the attack remotely. The exploit is now public and may be used.
Published Date July 13, 2026
Official Source NIST NVD Advisory