Impact
A vulnerability in the login.php file of Mstfakts College‑Management‑System allows an attacker to manipulate the email argument and bypass authentication. The flaw is an instance of Improper Authentication (CWE‑287) and can enable unauthorized users to gain access to application functions that require valid credentials. The vulnerability can be exploited remotely by sending crafted requests to the login endpoint.
Affected Systems
All publicly available releases of the Mstfakts College‑Management‑System are impacted, as the vendor’s rolling‑release model currently does not specify fixed versions. Because the project has not released a patch yet, any deployed instance of the application continues to be vulnerable until an update is applied.
Risk and Exploitability
The severity of the flaw is reflected in the CVSS score of 6.9, indicating moderate to high risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but its public disclosure and remote nature mean it can be exploited without local access. Attackers could simply send malformed email parameters to the login endpoint from the internet, making the exploitation straightforward and potentially widespread.
OpenCVE Enrichment