Impact
The flaw exists in signup.php, where the role argument can be manipulated to gain higher privileges. This improper privilege assignment can grant a user administrative access without authorization, allowing the attacker to perform actions that should be restricted by the application.
Affected Systems
SourceCodester College Notes Gallery Management System version 1.0.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. The EPSS score of < 1% indicates a very low but nonzero exploitation probability, while the vulnerability has been publicly disclosed and can be exploited remotely, suggesting a non-negligible risk. The vulnerability is not listed in CISA KEV, but its remote nature and publicly disclosed exploit imply that attackers could target affected installations.
OpenCVE Enrichment