Executive brief
The College-Management-System is a web-based platform for managing student and faculty accounts and records. The registration form accepts any email address without verifying email ownership or user eligibility, allowing attackers to claim pre-existing student or lecturer identities. Once claimed, an attacker gains access to sensitive academic and personal records including grades, transcripts, and scholarship details, and can modify profile data such as club memberships.
Technical details
The vulnerability is an improper authentication flaw (CWE-287) in the registration and login flow. The application maintains separate login records (visitor table) from business identities (student and lecturer tables), linking them solely by email address. The registration form accepts arbitrary emails without email verification or invitation validation and only checks whether the email exists in the visitor table; it fails to verify that the applicant is entitled to claim the supplied identity. An unauthenticated attacker can remotely register using a pre-provisioned student or lecturer email, then authenticate with their attacker-chosen password to gain full access to that identity's protected records and permissions. The application then treats the authenticated email as the authoritative student/lecturer identity. No patch has been released; the project uses rolling release and has not responded to the issue report.
Affected products
- Mstfakts College-Management-System Rolling release (unpatched as of 2026-09-06)
Timeline
- 2026-07-20: disclosed: Issue reported on GitHub
- 2026-09-06: advisory: CVE-2026-86214 published
- 2026-09-06: other: Project has not yet responded to vulnerability report