Executive brief
A security vulnerability exists in the CollegeManagementSystem, a platform used by engineering colleges to manage student records, staff, and attendance. An attacker can send a specially crafted request that executes malicious code in the web browser of a legitimate user. This could allow an attacker to steal login sessions, perform unauthorized actions on behalf of staff or students, or deface the management portal.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in the fetch_subject_data action within /dashboard_page/forms/fetch.php. The application fails to sanitize or output-encode the 'department_name' POST parameter before echoing it into an HTML table cell (<td>). An attacker can exploit this by crafting a malicious POST request that, when processed and rendered by a victim's browser (typically via an AJAX callback), executes arbitrary JavaScript. This can lead to session hijacking, CSRF, or unauthorized data modification. As of the advisory date, the project operates on a rolling release basis and has not yet responded to the reported issue.
Affected products
- tittuvarghese CollegeManagementSystem commit 3e476335cfbfb9a049e09f474c7ec885f69a9df3
Timeline
- 2026-05-18: disclosed: Issue reported on GitHub repository
- 2026-06-05: advisory: CVE published to NVD