CyberRota Analysis
AI-GeneratedA SQL injection vulnerability exists in the Search Handler component of the Mstfakts College Management System, specifically within the mysqli_query function in the university.php file. This flaw allows remote attackers to manipulate the book_name or book_author parameters, potentially leading to unauthorized access to the database. Organizations using this system should prioritize remediation efforts, especially given the public availability of the exploit and the lack of a disclosed fix.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability was found in Mstfakts College-Management-System. This issue affects the function mysqli_query of the file Front-end/university.php of the component Search Handler. The manipulation of the argument book_name/book_author results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.