Description
A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /College/login.php. The manipulation of the argument User leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
Published: 2026-09-15
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a classic SQL injection flaw in the login.php script of SourceCodester College Notes Gallery Management System. Attackers can manipulate the User parameter to inject arbitrary SQL and extract data, modify records, or cause denial of service. The weakness maps to CWE-74 and CWE-89.

Affected Systems

Affected are users running version 1.0 of SourceCodester College Notes Gallery Management System, which deploys the login.php file for authentication on web servers.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium impact, and the EPSS score of less than 1% suggests a very low likelihood of exploitation for the time being. Attackers can initiate the exploit remotely and may bypass authentication or exfiltrate data. The vulnerability is not listed in CISA KEV.

Generated by OpenCVE AI on September 17, 2026 at 18:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Obtain and install any vendor‑published patch or newer release that sanitizes the User parameter in login.php.
  • Until a patch is available, replace raw SQL queries with parameterized statements or escape user input to prevent injection.
  • Restrict web access to the login.php endpoint to trusted IP addresses or implement a Web Application Firewall to block suspicious SQL payloads.
  • Update database credentials and enforce least privilege on the database account used by the application.

Generated by OpenCVE AI on September 17, 2026 at 18:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /College/login.php. The manipulation of the argument User leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
Title SourceCodester College Notes Gallery Management System login.php sql injection
First Time appeared Sourcecodester
Sourcecodester college Notes Gallery Management System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:sourcecodester:college_notes_gallery_management_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester college Notes Gallery Management System
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester College Notes Gallery Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T13:56:01.760Z

Reserved: 2026-09-14T05:28:43.950Z

Link: CVE-2026-90849

cve-icon Vulnrichment

Updated: 2026-09-15T13:55:53.666Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T02:16:48.960

Modified: 2026-09-15T14:37:14.523

Link: CVE-2026-90849

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:00:17Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')