users_adm/start1.php in IMGallery 2.5 and earlier does not properly handle files with multiple extensions, which allows remote authenticated users to upload and execute arbitrary PHP scripts.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.021
EPSS Ranking 80.7%