Description
A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. This impacts an unknown function of the file signup.php of the component Registration Flow. Such manipulation of the argument role leads to improper privilege management. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
Published: 2026-09-15
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

The flaw exists in signup.php, where the role argument can be manipulated to gain higher privileges. This improper privilege assignment can grant a user administrative access without authorization, allowing the attacker to perform actions that should be restricted by the application.

Affected Systems

SourceCodester College Notes Gallery Management System version 1.0.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. The EPSS score of < 1% indicates a very low but nonzero exploitation probability, while the vulnerability has been publicly disclosed and can be exploited remotely, suggesting a non-negligible risk. The vulnerability is not listed in CISA KEV, but its remote nature and publicly disclosed exploit imply that attackers could target affected installations.

Generated by OpenCVE AI on September 17, 2026 at 18:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest version of SourceCodester College Notes Gallery Management System that corrects the role handling logic.
  • If an immediate upgrade is not possible, enforce strict role validation on the server side or disable the signup functionality until a fix is applied.
  • Continuously monitor application logs for unauthorized role changes or suspicious signup activity.

Generated by OpenCVE AI on September 17, 2026 at 18:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. This impacts an unknown function of the file signup.php of the component Registration Flow. Such manipulation of the argument role leads to improper privilege management. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
Title SourceCodester College Notes Gallery Management System Registration Flow signup.php privileges management
First Time appeared Sourcecodester
Sourcecodester college Notes Gallery Management System
Weaknesses CWE-266
CWE-269
CPEs cpe:2.3:a:sourcecodester:college_notes_gallery_management_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester college Notes Gallery Management System
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester College Notes Gallery Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T13:54:14.214Z

Reserved: 2026-09-14T05:50:46.224Z

Link: CVE-2026-90856

cve-icon Vulnrichment

Updated: 2026-09-15T13:47:14.867Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T03:17:06.910

Modified: 2026-09-15T14:37:14.523

Link: CVE-2026-90856

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:00:17Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-269

    Improper Privilege Management