CVE-2026-90856: SourceCodester College Notes Gallery Management System Registration Flow signup.php privileges management
A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. This impacts an unknown function of the file signup.php of the component Registration Flow. Such manipulation of the argument role leads to improper privilege management. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote, unauthenticated attacker can exploit the vulnerable registration flow. No user interaction or existing privileges are indicated as necessary.
What access could an attacker gain?
Manipulating the role argument in signup.php can result in improper privilege management. The available data does not specify which elevated role or permissions can be obtained.
Is there public exploit information?
Yes. The exploit has been publicly disclosed and may be used, increasing the likelihood of attempted exploitation.
How can I determine whether my deployment is affected?
Deployments of SourceCodester College Notes Gallery Management System version 1.0 should be considered affected based on the available information. Review the registration endpoint and signup.php handling of the role argument for user-controlled privilege assignment.