Junglewise Threat Intelligence

CVE-2026-15539: SourceCodester Online Book Store System unrestricted upload in Book Image Feature

CVE-2026-15539 · Severity: medium · CVSS 4.7 · Published 2026-07-13

Technologies: SourceCodester Online Book Store System. Vendors: SourceCodester.

Executive brief

A security vulnerability exists in the SourceCodester Online Book Store System, a web application used for managing book sales. An attacker with administrative access can upload malicious files to the server through the book image upload feature. This could allow an attacker to take control of the website, access sensitive data, or disrupt business operations.

Technical details

An unrestricted file upload vulnerability exists in SourceCodester Online Book Store System 1.0 within the Book Image Upload feature. The flaw is located in the /admin/index.php?page=books component, where the application fails to properly validate the type or content of uploaded files. A remote attacker with high privileges (administrative access) can exploit this to upload dangerous file types, such as PHP scripts, to the web server. Successful exploitation can lead to Remote Code Execution (RCE) on the underlying host. As of the advisory date, no official patch has been identified for this version.

Affected products

  • SourceCodester Online Book Store System 1.0

Timeline

  • 2026-07-13: advisory: Vulnerability published by NVD/VulDB
  • 2026-07-13: disclosed: Public exploit disclosed via Medium post

References

Related threats