PT-2026-23895 · Sourcecodester · Modern Image Gallery App

Hackus_Man

·

Published

2026-03-08

·

Updated

2026-03-09

·

CVE-2026-3695

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions SourceCodester Modern Image Gallery App version 1.0
Description A path traversal issue exists in SourceCodester Modern Image Gallery App version 1.0. The issue is located in the /delete.php file, specifically affecting an unknown function. Manipulation of the filename argument allows for path traversal, enabling remote attacks. The exploit details have been publicly disclosed.
Recommendations As a temporary workaround, consider restricting access to the /delete.php file until a patch is available.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-3695

Affected Products

Modern Image Gallery App