Impact
The vulnerability resides in the Logout Handler component of the College Management System. Manipulating the log_out argument in the server.php script causes the application to terminate user sessions prematurely. This results in a denial‑of‑service to logged‑in users but does not allow an attacker to execute arbitrary code. The weakness is identified as insufficient session expiration protection.
Affected Systems
The affected product is Mstfakts College Management System. Version information is not available because the project follows a rolling‑release model, so any currently deployed instance of the software may be susceptible.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact. EPSS data are not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not known to be actively exploited in the wild. However, the public exploitation references and ability to trigger the issue remotely make it feasible for attackers to disrupt sessions in any exposed installation of the system.
OpenCVE Enrichment