CVE-2026-37749

CRITICAL

Simple Attendance Management System 1.0 - SQL Injection

Title source: llm

Description

A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attackers to bypass authentication via the username parameter in index.php.

Scores

CVSS v3 9.8
EPSS 0.0007
EPSS Percentile 21.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Published Apr 17, 2026
Tracked Since Apr 17, 2026