Executive brief
The Mstfakts College-Management-System is a web-based university management platform that allows students and faculty to search a library catalog. An unauthenticated attacker can inject malicious SQL commands through the book search functionality to extract sensitive database records, including user email addresses, password hashes, phone numbers, and account roles, bypassing all access controls.
Technical details
This is a classic SQL injection vulnerability (CWE-89) in the book search handler of Front-end/university.php and Front-end/faculty.php. The vulnerable code directly concatenates unsanitized POST parameters (book_name and book_author) into a SQL SELECT query without using prepared statements or parameterized queries. The search function is unauthenticated and network-reachable, allowing any remote user to craft UNION SELECT payloads to exfiltrate data from other database tables (e.g., the visitor table containing credentials). An attacker can disclose account identities, password hashes, phone numbers, and roles. The project uses a rolling release model and has not yet patched the issue despite early notification via GitHub issue report.
Affected products
- Mstfakts College-Management-System All versions including commit 82ab01d057d96c8893c419cd9cb6870120faaea3 and prior
Timeline
- 2026-07-20: disclosed: Vulnerability reported via GitHub issue #5
- 2026-09-06: advisory: CVE-2026-86213 published on NVD