A SQL injection vulnerability has been identified in the Mstfakts College-Management-System, specifically in the mysqli_query function within the file Front-end/university.php under the Search Handler component. The vulnerability is triggered by manipulating the book_name or book_author arguments, allowing an attacker to perform SQL injection remotely. A public exploit is available, increasing the risk of exploitation. The product uses a rolling release model, so no specific version information is disclosed for affected or patched releases. The vendor was notified via a GitHub issue report but has not yet responded. The vulnerability has been catalogued in VulDB and NVD. No patch or mitigation has been confirmed at this time, leaving users exposed.