Unrated severityNVD Advisory· Published Jul 13, 2026· Updated Jul 13, 2026
SourceCodester Online Book Store System Administrative index.php php file inclusion
CVE-2026-15540
Description
A vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is an unknown function of the file /admin/index.php of the component Administrative Interface. Performing a manipulation of the argument page results in improper control of filename for include/require statement in php program. It is possible to initiate the attack remotely. The exploit is now public and may be used.
Affected products
1- Range: 1.0
Patches
Vulnerability mechanics
References
6- medium.com/@hemantrajbhati5555/local-file-inclusion-lfi-via-page-parameter-leading-to-source-code-disclosure-ce722de0c407mitrebroken-linkexploit
- vuldb.com/cve/CVE-2026-15540mitrethird-party-advisory
- vuldb.com/submit/855048mitrethird-party-advisory
- vuldb.com/vuln/377890mitrevdb-entrytechnical-description
- vuldb.com/vuln/377890/ctimitresignaturepermissions-required
- www.sourcecodester.commitreproduct
News mentions
0No linked articles in our index yet.