CVE-2026-86215CWE-613

CVE-2026-86215

Medium · published September 6, 2026

CVSS v3.1
4.3
EPSS
In the wild
Unconfirmed
What it is

A vulnerability was identified in Mstfakts College-Management-System. The affected element is an unknown function of the file Front-end/server.php of the component Logout Handler. Such manipulation of the argument log_out leads to session expiration. It is possible to launch the attack remotely. The exploit is publicly available and might be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.

The record
Technical detail
CVSS v3.1
4.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS v4.0
5.3 · CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
EPSS
Not scored
Weakness
CWE-613 · Insufficient Session Expiration
Published
2026-09-06T18:17Z
References (6)
Timeline
  • 06 SEP 13:15Z
    Mstfakts College-Management-System Logout server.php session expiration
    cvelistv5