Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 26 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 26 Jan 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-434 | |
| Metrics |
cvssV3_1
|
Mon, 26 Jan 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sourcecodester
Sourcecodester modern Image Gallery App |
|
| Vendors & Products |
Sourcecodester
Sourcecodester modern Image Gallery App |
Fri, 23 Jan 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/upload.php component. The application fails to properly validate uploaded file contents. Additionally, the application preserves the user-supplied file extension during the save process. This allows an unauthenticated attacker to upload arbitrary PHP code by spoofing the MIME type as an image, leading to full system compromise. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-01-26T15:44:45.929Z
Reserved: 2026-01-09T00:00:00.000Z
Link: CVE-2025-70457
Updated: 2026-01-26T15:44:14.800Z
Status : Undergoing Analysis
Published: 2026-01-23T22:16:15.243
Modified: 2026-01-26T16:15:59.173
Link: CVE-2025-70457
No data.
OpenCVE Enrichment
Updated: 2026-01-26T11:54:13Z