CVE-2025-70457
Last modified
CVE-2025-70457 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/upload.php component. The application fails to properly validate uploaded file contents. EPSS estimates a 0.83% chance of exploitation in the next 30 days.
Description
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/upload.php component. The application fails to properly validate uploaded file contents. Additionally, the application preserves the user-supplied file extension during the save process. This allows an unauthenticated attacker to upload arbitrary PHP code by spoofing the MIME type as an image, leading to full system compromise.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Remyandrade | Modern Image Gallery App | 1.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-70457?
How severe is CVE-2025-70457?
How do I fix CVE-2025-70457?
Are you affected by CVE-2025-70457?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
