CVE-2026-86213: Mstfakts College-Management-System Search university.php mysqli_query sql injection
A vulnerability was found in Mstfakts College-Management-System. This issue affects the function mysqliquery of the file Front-end/university.php of the component Search Handler. The manipulation of the argument bookname/bookauthor results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack can be performed remotely and requires no privileges or user interaction. Exploitation targets the Search Handler through the book_name or book_author arguments.
Is public exploit information available?
Yes. The exploit has been made public, which increases the likelihood that the issue could be used against exposed deployments.
Which releases are affected or fixed?
Specific affected and updated release versions are not disclosed because the product uses a rolling release system. The project was notified through an issue report but had not responded at the time of the report.