Impact
The vulnerability involves an unrestricted file upload in the /dashboard/userprofile.php component of College Notes Gallery Management System. Manipulating the image argument allows an attacker to upload any file, and if a malicious script is uploaded, it could potentially be executed on the server. Based on the description, it is inferred that this upload flaw could lead to remote code execution, though the CVE text does not explicitly state that execution will occur. The flaw is rooted in improper access control (CWE-284) and a failure to validate file types (CWE-434).
Affected Systems
SourceCodester College Notes Gallery Management System 1.0 is affected. The issue resides in the, it is inferred that the issue is not limited by user role or other restrictions.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity rating. The EPSS score of < 1% suggests a very low probability of exploitation currently, and the vulnerability is not listed in the CISA KEV catalog. Based on the unrestricted upload capability and the fact that the exploit is publicly available, it is inferred that an attacker could potentially upload malicious files that might be executed on the server, leading to compromise of user data and application integrity.
OpenCVE Enrichment