Description
A vulnerability was determined in Mstfakts College-Management-System. Impacted is an unknown function of the file Front-end/login.php. This manipulation of the argument email causes improper authentication. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-06
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the login.php file of Mstfakts College‑Management‑System allows an attacker to manipulate the email argument and bypass authentication. The flaw is an instance of Improper Authentication (CWE‑287) and can enable unauthorized users to gain access to application functions that require valid credentials. The vulnerability can be exploited remotely by sending crafted requests to the login endpoint.

Affected Systems

All publicly available releases of the Mstfakts College‑Management‑System are impacted, as the vendor’s rolling‑release model currently does not specify fixed versions. Because the project has not released a patch yet, any deployed instance of the application continues to be vulnerable until an update is applied.

Risk and Exploitability

The severity of the flaw is reflected in the CVSS score of 6.9, indicating moderate to high risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but its public disclosure and remote nature mean it can be exploited without local access. Attackers could simply send malformed email parameters to the login endpoint from the internet, making the exploitation straightforward and potentially widespread.

Generated by OpenCVE AI on September 6, 2026 at 15:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Monitor the vendor’s repository for an official patch and apply it promptly when released.
  • Restrict access to the login endpoint by limiting incoming IP addresses or implementing basic authentication.
  • Modify the login handler to sanitize and validate the email input, rejecting malformed requests to prevent authentication bypass.

Generated by OpenCVE AI on September 6, 2026 at 15:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 06 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Mstfakts
Mstfakts college-management-system
Vendors & Products Mstfakts
Mstfakts college-management-system

Sun, 06 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Mstfakts College-Management-System. Impacted is an unknown function of the file Front-end/login.php. This manipulation of the argument email causes improper authentication. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Title Mstfakts College-Management-System login.php improper authentication
First Time appeared Mstfakts College-management-system
Mstfakts College-management-system mstfakts College-management-system
Weaknesses CWE-287
CPEs cpe:2.3:a:mstfakts_college-management-system:mstfakts_college-management-system:*:*:*:*:*:*:*:*
Vendors & Products Mstfakts College-management-system
Mstfakts College-management-system mstfakts College-management-system
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Mstfakts College-management-system
Mstfakts College-management-system Mstfakts College-management-system
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-06T13:00:07.452Z

Reserved: 2026-09-05T18:59:12.286Z

Link: CVE-2026-86214

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-06T13:17:10.667

Modified: 2026-09-06T13:17:10.667

Link: CVE-2026-86214

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-06T16:00:12Z

Weaknesses