What is CVE-2026-19230?
A Cross-Site Scripting (XSS) vulnerability was found in SourceCodester Photo Share Website 1.0, affecting the Comment Input Box via the `/social/ajax.php?action=save_upload` file. By manipulating the `content` argument, a remote attacker can inject malicious scripts. Users should contact the vendor and enforce strict input sanitization.
Azərbaycanca: SourceCodester Photo Share Website 1.0-un Comment Input Box komponentində XSS zəifliyi aşkarlanıb. Uzaqdan hücum edən şəxs `/social/ajax.php?action=save_upload` faylındakı `content` arqumentini manipulyasiya edərək zərərli skript icra edə bilər. İstifadəçilərə dərhal satıcıya müraciət edib, giriş validasiyasını gücləndirmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: SourceCodester
FAQ2
Which component in SourceCodester Photo Share Website 1.0 is affected by the XSS vulnerability?
The Comment Input Box component is affected via the `content` argument in the `/social/ajax.php?action=save_upload` file.
What must a remote attacker manipulate to exploit CVE-2026-19230?
A remote attacker must manipulate the `content` argument in the `/social/ajax.php?action=save_upload` file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.