Search Results (1 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-70457 1 Sourcecodester 1 Modern Image Gallery App 2026-01-26 N/A
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/upload.php component. The application fails to properly validate uploaded file contents. Additionally, the application preserves the user-supplied file extension during the save process. This allows an unauthenticated attacker to upload arbitrary PHP code by spoofing the MIME type as an image, leading to full system compromise.