CVE-2026-95828 Details
Description
A vulnerability was determined in Mstfakts College-Management-System. This affects the function session_start of the file Front-end/server.php of the component Authentication. Executing a manipulation can lead to session fixiation. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.
A session fixation vulnerability has been identified in the Mstfakts College Management System, specifically within the authentication component. The issue arises in the Front-end/server.php file, where the application fails to properly manage session identifiers during the login process. By not rotating the PHP session ID after successful authentication, the application allows an attacker to exploit a known session identifier, potentially leading to unauthorized access to user accounts. This vulnerability can be exploited remotely.
To address this vulnerability, the session identifier should be regenerated immediately after successful authentication in all login processes. Additionally, enabling strict mode in the PHP configuration can provide an extra layer of security.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 22, 2026CISA-ADP
Assessed Sep 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Mstfakts/College-Management-System/issues/8 | CISA-ADP | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/Mstfakts/College-Management-System/ | [email protected] | ProductVendor |
| https://github.com/Mstfakts/College-Management-System/issues/8 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://vuldb.com/cve/CVE-2026-95828 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/897267 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/408521 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/408521/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-384 | Session Fixation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Mstfakts College-Management-System | 82ab01d057d96c8893c419cd9cb6870120faaea3 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 23, 2026 | CVE Modified | CISA-ADP |
| Sep 22, 2026 | New CVE Received | [email protected] |
Volerion