Description
A vulnerability was determined in Mstfakts College-Management-System. Impacted is an unknown function of the file Front-end/login.php. This manipulation of the argument email causes improper authentication. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-06
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 06 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Mstfakts
Mstfakts college-management-system
Vendors & Products Mstfakts
Mstfakts college-management-system

Sun, 06 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Mstfakts College-Management-System. Impacted is an unknown function of the file Front-end/login.php. This manipulation of the argument email causes improper authentication. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Title Mstfakts College-Management-System login.php improper authentication
First Time appeared Mstfakts College-management-system
Mstfakts College-management-system mstfakts College-management-system
Weaknesses CWE-287
CPEs cpe:2.3:a:mstfakts_college-management-system:mstfakts_college-management-system:*:*:*:*:*:*:*:*
Vendors & Products Mstfakts College-management-system
Mstfakts College-management-system mstfakts College-management-system
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Mstfakts College-management-system
Mstfakts College-management-system Mstfakts College-management-system
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-08T15:05:11.302Z

Reserved: 2026-09-05T18:59:12.286Z

Link: CVE-2026-86214

cve-icon Vulnrichment

Updated: 2026-09-08T15:05:08.391Z

cve-icon NVD

Status : Deferred

Published: 2026-09-06T13:17:10.667

Modified: 2026-09-08T16:18:22.333

Link: CVE-2026-86214

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-06T16:00:12Z

Weaknesses