CVE-2026-37749
CRITICALSimple Attendance Management System 1.0 - SQL Injection
Title source: llmDescription
A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attackers to bypass authentication via the username parameter in index.php.
Scores
CVSS v3
9.8
EPSS
0.0007
EPSS Percentile
21.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-89
Status
published
Published
Apr 17, 2026
Tracked Since
Apr 17, 2026