Junglewise Threat Intelligence

CVE-2026-90849: SourceCodester College Notes Gallery Management System SQL injection in login

CVE-2026-90849 · Severity: high · CVSS 7.3 · Published 2026-09-15

Technologies: SourceCodester College Notes Gallery Management System. Vendors: SourceCodester.

Executive brief

College Notes Gallery Management System is a PHP-based web application for managing educational notes and galleries. A SQL injection vulnerability in the login page allows attackers to bypass authentication, access sensitive student and faculty data, and potentially modify or delete records in the underlying database without requiring valid credentials.

Technical details

A SQL injection vulnerability exists in the 'user' parameter of the /College/login.php file in College Notes Gallery Management System version 1.0. The vulnerability stems from insufficient input validation and sanitization—user-supplied input from the 'user' POST parameter is directly concatenated into SQL queries without prepared statements or parameterized queries. The attack is network-accessible and requires no authentication or user interaction. An attacker can craft malicious SQL payloads (boolean-blind, error-based, or time-based blind techniques) to extract database contents, modify data, or bypass login restrictions. No patch is currently available; remediation requires implementing prepared statements with parameter binding and strict input validation.

Affected products

  • SourceCodester College Notes Gallery Management System 1.0

Timeline

  • 2026-08-13: disclosed: Vulnerability disclosed on GitHub
  • 2026-09-15: advisory: CVE-2026-90849 published

References

Related threats