---
id: CVE-2026-15539
title: >-
  A security vulnerability has been detected in SourceCodester Online Book Store
  System 1.0
summary: >-
  A security vulnerability has been detected in SourceCodester Online Book Store
  System 1.0. Impacted is an unknown function of the file
  /admin/index.php?page=books of the component Book Image Upload Feature. Such
  manipulation leads to unr…
severity: medium
cvss: 4.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-284
  - CWE-434
published: '2026-07-13'
updated: '2026-07-13'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15539'
references:
  - url: >-
      https://medium.com/@hemantrajbhati5555/critical-authenticated-remote-code-execution-rce-via-unrestricted-file-upload-5a4a313ea1f1
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-15539'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/855046'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/377889'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/377889/cti'
    label: cna@vuldb.com
  - url: 'https://www.sourcecodester.com/'
    label: cna@vuldb.com
tags:
  - nvd
ingestedAt: '2026-07-13T09:25:32.849Z'
epss: 0.00396
epssPercentile: 0.31091
---

## Overview

A security vulnerability has been detected in SourceCodester Online Book Store System 1.0. Impacted is an unknown function of the file /admin/index.php?page=books of the component Book Image Upload Feature. Such manipulation leads to unrestricted upload. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
