Cross Site Scripting Vulnerability in SourceCodester Modern Image Gallery App
CVE-2026-3070
5.3MEDIUM
Key Information:
- Vendor
Sourcecodester
- Status
- Vendor
- CVE Published:
- 24 February 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-3070?
The SourceCodester Modern Image Gallery App version 1.0 is susceptible to a cross site scripting vulnerability through its upload.php file. An attacker can exploit this by manipulating the 'filename' parameter, potentially launching the attack remotely. This exploit is now publicly available, highlighting the necessity for immediate security measures to safeguard users against potential threats.
Affected Version(s)
Modern Image Gallery App 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
SHU for security (VulDB User)
