rootpwn

high · CVSS v3 7.3 · CVSS v4 6.9

CVE-2026-95819

CVE-2026-95819 is a high severity SQL injection flaw in the login.php of anirbandutta9 College-Notes-Gallery. Remote attackers can inject SQ

Overview

CVE-2026-95819 is a high severity SQL injection flaw in the login.php of anirbandutta9 College-Notes-Gallery. Remote attackers can inject SQL via the user/pass parameters, potentially compromising the database. The vulnerability exists in all releases up to a specific commit and remains unpatched.

Description

A vulnerability has been found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6. Affected by this vulnerability is an unknown functionality of the file login.php. Such manipulation of the argument user/pass leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The vendor was contacted early about this disclosure but did not respond in any way.

Impact

The flaw allows attackers to read, modify, or delete database contents, compromising confidentiality, integrity, and availability of student data. Defenders should consider the risk of data exposure and potential service disruption. The vulnerability is exploitable remotely without authentication.

Remediation

Apply the vendor's patch or upgrade to a version that includes the fix. If no patch is available, implement input validation and parameterized queries on the login.php endpoint. Additionally, restrict access to the login page via firewall rules or IP whitelisting.

Risk context

Severity is high with CVSS v3 score 7.3. No EPSS data is available, but the public disclosure and lack of vendor response increase urgency. Defenders should treat this as a critical patch priority.

Affected products

  • anirbandutta9 College-Notes-Gallery

Scores

Severity
high
CVSS v2
7.5
CVSS v3
7.3
CVSS v4
6.9
EPSS

sql-injection remote web-application authentication database high-severity unpatched

← All CVEs