Description
A vulnerability has been found in SourceCodester Modern Image Gallery App 1.0. Impacted is an unknown function of the file /delete.php. Such manipulation of the argument filename leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Problem types
Product status
Timeline
| 2026-02-19: | Vulnerability found |
| 2026-03-07: | Advisory disclosed |
| 2026-03-07: | Exploit disclosed |
| 2026-03-07: | VulDB entry created |
| 2026-03-08: | VulDB entry last update |
Credits
Atter Koffi Kallern
hackus_man (VulDB User)
hackus_man (VulDB User)
References
vuldb.com/?id.349641 (VDB-349641 | SourceCodester Modern Image Gallery App delete.php path traversal)
vuldb.com/?ctiid.349641 (VDB-349641 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.765591 (Submit #765591 | SourceCodester Modern Image Gallery App v1.0 Path Traversal)
gist.github.com/hackusman/e618b915514ed24b9333c72152bb7218
gist.github.com/hackusman/e618b915514ed24b9333c72152bb7218
www.sourcecodester.com/