Junglewise Threat Intelligence

CVE-2026-86215: Mstfakts College-Management-System insufficient session expiration in logout handler

CVE-2026-86215 · Severity: medium · CVSS 4.3 · Published 2026-09-06

Executive brief

Mstfakts College-Management-System is a web-based application that manages student and lecturer accounts for universities. A flaw in the logout function fails to properly invalidate user sessions, allowing anyone with a saved session cookie—including users of shared computers or attackers who captured a token—to continue accessing protected profile data and account information after the legitimate owner has logged out.

Technical details

The vulnerability is insufficient session expiration (CWE-613) in the logout handler (Front-end/server.php, lines 125–129). When a user logs out, the application performs only client-side navigation to login.php via JavaScript, but never destroys the PHP session or expires the PHPSESSID cookie. An attacker who possesses a valid session identifier can reuse it to access protected pages, retrieve sensitive profile data (email, GPA, student ID, academic information), and execute authenticated actions. The attack is network-accessible and requires no privileges, but does require that an attacker either has physical access to a shared workstation or previously captured a session cookie. No server-side fixes are publicly available; the project maintainers have not responded to the initial report.

Affected products

  • Mstfakts College-Management-System Rolling release; version details not available

Timeline

  • 2026-07-20: disclosed: Vulnerability reported via GitHub issue #7
  • 2026-09-06: advisory: CVE-2026-86215 published on NVD

References