Executive brief
Mstfakts College-Management-System is a web-based application that manages student and lecturer accounts for universities. A flaw in the logout function fails to properly invalidate user sessions, allowing anyone with a saved session cookie—including users of shared computers or attackers who captured a token—to continue accessing protected profile data and account information after the legitimate owner has logged out.
Technical details
The vulnerability is insufficient session expiration (CWE-613) in the logout handler (Front-end/server.php, lines 125–129). When a user logs out, the application performs only client-side navigation to login.php via JavaScript, but never destroys the PHP session or expires the PHPSESSID cookie. An attacker who possesses a valid session identifier can reuse it to access protected pages, retrieve sensitive profile data (email, GPA, student ID, academic information), and execute authenticated actions. The attack is network-accessible and requires no privileges, but does require that an attacker either has physical access to a shared workstation or previously captured a session cookie. No server-side fixes are publicly available; the project maintainers have not responded to the initial report.
Affected products
- Mstfakts College-Management-System Rolling release; version details not available
Timeline
- 2026-07-20: disclosed: Vulnerability reported via GitHub issue #7
- 2026-09-06: advisory: CVE-2026-86215 published on NVD