Description
A vulnerability was detected in SourceCodester College Notes Gallery Management System 1.0. Affected is an unknown function of the file /dashboard/userprofile.php of the component Profile Upload. Performing a manipulation of the argument image results in unrestricted upload. The attack may be initiated remotely. The exploit is now public and may be used.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unrestricted File Upload
Action: Apply Patch
AI Analysis

Impact

The vulnerability involves an unrestricted file upload in the /dashboard/userprofile.php component of College Notes Gallery Management System. Manipulating the image argument allows an attacker to upload any file, and if a malicious script is uploaded, it could potentially be executed on the server. Based on the description, it is inferred that this upload flaw could lead to remote code execution, though the CVE text does not explicitly state that execution will occur. The flaw is rooted in improper access control (CWE-284) and a failure to validate file types (CWE-434).

Affected Systems

SourceCodester College Notes Gallery Management System 1.0 is affected. The issue resides in the, it is inferred that the issue is not limited by user role or other restrictions.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium severity rating. The EPSS score of < 1% suggests a very low probability of exploitation currently, and the vulnerability is not listed in the CISA KEV catalog. Based on the unrestricted upload capability and the fact that the exploit is publicly available, it is inferred that an attacker could potentially upload malicious files that might be executed on the server, leading to compromise of user data and application integrity.

Generated by OpenCVE AI on September 17, 2026 at 18:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Obtain and deploy an updated version of the SourceCodester College Notes Gallery Management System that removes the unrestricted upload option or introduces proper access controls.
  • Configure the upload endpoint to validate MIME types and file extensions against an approved list (e.g., only image/jpeg, image/png) and reject any nonconforming uploads.
  • Move the upload directory outside of the web‑root or enforce a server‑side script that sanitizes uploaded files before making them accessible to prevent direct execution or browsing.

Generated by OpenCVE AI on September 17, 2026 at 18:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in SourceCodester College Notes Gallery Management System 1.0. Affected is an unknown function of the file /dashboard/userprofile.php of the component Profile Upload. Performing a manipulation of the argument image results in unrestricted upload. The attack may be initiated remotely. The exploit is now public and may be used.
Title SourceCodester College Notes Gallery Management System Profile Upload userprofile.php unrestricted upload
First Time appeared Sourcecodester
Sourcecodester college Notes Gallery Management System
Weaknesses CWE-284
CWE-434
CPEs cpe:2.3:a:sourcecodester:college_notes_gallery_management_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester college Notes Gallery Management System
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester College Notes Gallery Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T13:54:33.464Z

Reserved: 2026-09-14T05:50:49.462Z

Link: CVE-2026-90857

cve-icon Vulnrichment

Updated: 2026-09-15T13:54:28.423Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T04:18:19.700

Modified: 2026-09-15T14:37:14.523

Link: CVE-2026-90857

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:00:17Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-434

    Unrestricted Upload of File with Dangerous Type