Sceawere

Vulnerability Detail

CVE-2026-19209UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Photo Share Website Cross Site Scripting

Vulnerability Metadata

Severity
Low
Score / CVSS
3.5
Creation Date
21h ago
Vendor
SourceCodester
Product
Photo Share Website
Attack Type
Cross Site Scripting
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

A flaw has been found in SourceCodester Photo Share Website 1.0. The affected element is an unknown function of the file /social/index.php?page=home. This manipulation of the argument Comment causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.5",
  "pubDate": "2026-08-07T16:17:23.933Z",
  "pubdate": "2026-08-07T16:17:23.933Z",
  "executiveSummary": "A Cross-Site Scripting (XSS) vulnerability has been identified in SourceCodester Photo Share Website 1.0. The security flaw resides within an unknown function in the file /social/index.php?page=home, specifically triggered via the manipulation of the Comment argument. This vulnerability allows remote attackers to inject malicious client-side scripts, typically JavaScript, into web pages viewed by other users.\nThe impact of successful exploitation includes session hijacking, credential theft, redirection to malicious websites, and unauthorized actions performed on behalf of the victim within the application context. The affected system is SourceCodester Photo Share Website version 1.0. Given that a public exploit has been published, the risk of automated or targeted attacks is elevated.\nAttackers do not necessarily require prior authentication depending on application accessibility, and the attack vector is fully remote over network protocols. Exploitation requires user interaction, such as an authenticated or unauthenticated user viewing the compromised page containing the injected comment payload.",
  "technicalDetails": "The vulnerability is classified as a Cross-Site Scripting (XSS) flaw stemming from improper neutralization of user-supplied input during web page generation. The vulnerable component is located within the application logic processing comments in the file /social/index.php?page=home, specifically handling the Comment parameter.\nThe root cause of this vulnerability lies in the lack of adequate input sanitization and output encoding. When a user submits data via the Comment argument, the application processes and reflects the input back to the browser without sufficiently stripping or encoding executable HTML or JavaScript tags. Consequently, the browser interprets the malicious payload as legitimate code belonging to the web application.\nThe attack flow proceeds as follows: First, a remote attacker crafts a malicious payload containing arbitrary JavaScript enclosed within HTML tags, targeting the Comment parameter via the endpoint /social/index.php?page=home. Second, the attacker submits this payload to the server, where it is improperly stored or directly reflected in the application's response. Third, a victim visits the affected page and loads the rendered content containing the malicious comment. Finally, the victim's web browser executes the injected script within the context of their active session, allowing the attacker to steal session cookies, manipulate the Document Object Model (DOM), or perform unauthorized API requests.\nNetwork exposure is fully remote over HTTP/HTTPS protocols. The vulnerability impacts SourceCodester Photo Share Website 1.0. Privileges required to initiate the attack depend on whether comment submission is restricted to authenticated users, though public exploits suggest minimal friction for remote execution. Post-exploitation impact is typical of stored or reflected XSS vulnerabilities, including full compromise of the victim's interaction with the vulnerable web application."
}
CVE-2026-19209: Photo Share Website Cross Site Scripting (LOW Severity, CVSS: 3.5) - Sceawere