CVE-2026-95820 Details
Description
A vulnerability was found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6. Affected by this issue is some unknown functionality of the file /dashboard/userprofile.php?section=admin1. Performing a manipulation of the argument image results in unrestricted upload. It is possible to initiate the attack remotely. The exploit has been made public and could be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability exists in College-Notes-Gallery versions prior to commit 8c1cf3d98f30982d069c88ca172612c001eb39f6, specifically in the file 'dashboard/userprofile.php' when the 'section' parameter is set to 'admin1'. This vulnerability allows for unrestricted file uploads by manipulating the 'image' argument. The application fails to properly validate the file type, enabling the upload of malicious files, such as web shells, which could be used for remote code execution. The vulnerability can be exploited remotely, and the existence of a public exploit has been confirmed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 22, 2026CISA-ADP
Assessed Sep 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/yingxiujie/cve/issues/10 | [email protected] | ExploitIssue TrackingTechnical Description |
| https://vuldb.com/cve/CVE-2026-95820 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/897168 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/408520 | [email protected] | BundlePermission Required |
| https://vuldb.com/vuln/408520/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | [email protected] |
| CWE-434 | Unrestricted Upload of File with Dangerous Type | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| anirbandutta9 College-Notes-Gallery | <= 8c1cf3d98f30982d069c88ca172612c001eb39f6 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 23, 2026 | CVE Modified | CISA-ADP |
| Sep 22, 2026 | New CVE Received | [email protected] |
Volerion