CVE-2026-37749
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
17/04/2026
Last modified:
17/04/2026
Description
A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attackers to bypass authentication via the username parameter in index.php.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL



