SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-15540

MEDIUM · CVSS 4.3 EPSS 0.24% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

The SourceCodester Online Book Store System 1.0 has a vulnerability in the administrative interface, specifically within the /admin/index.php file, where improper handling of the 'page' argument allows for remote code execution through manipulated include/require statements. This could lead to unauthorized access or control over the system, making it critical for administrators of affected installations to prioritize patching or mitigating this vulnerability. Organizations using this system should take immediate action to safeguard against potential exploitation, as the exploit is now publicly available.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-15540
Severity
MEDIUM
CVSS
4.3
EPSS
0.24%

Original NVD Description

A vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is an unknown function of the file /admin/index.php of the component Administrative Interface. Performing a manipulation of the argument page results in improper control of filename for include/require statement in php program. It is possible to initiate the attack remotely. The exploit is now public and may be used.