Junglewise Threat Intelligence

CVE-2026-11337: tittuvarghese CollegeManagementSystem XSS in fetch.php

CVE-2026-11337 · Severity: medium · CVSS 4.3 · Published 2026-06-05

Technologies: Tittuvarghese CollegeManagementSystem, Tittuvarghese College Management System. Vendors: Tittuvarghese.

Executive brief

A security vulnerability exists in the CollegeManagementSystem, a platform used by engineering colleges to manage student records, staff, and attendance. An attacker can send a specially crafted request that executes malicious code in the web browser of a legitimate user. This could allow an attacker to steal login sessions, perform unauthorized actions on behalf of staff or students, or deface the management portal.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in the fetch_subject_data action within /dashboard_page/forms/fetch.php. The application fails to sanitize or output-encode the 'department_name' POST parameter before echoing it into an HTML table cell (<td>). An attacker can exploit this by crafting a malicious POST request that, when processed and rendered by a victim's browser (typically via an AJAX callback), executes arbitrary JavaScript. This can lead to session hijacking, CSRF, or unauthorized data modification. As of the advisory date, the project operates on a rolling release basis and has not yet responded to the reported issue.

Affected products

  • tittuvarghese CollegeManagementSystem commit 3e476335cfbfb9a049e09f474c7ec885f69a9df3

Timeline

  • 2026-05-18: disclosed: Issue reported on GitHub repository
  • 2026-06-05: advisory: CVE published to NVD

References

Related threats