CVE-2026-37749

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
17/04/2026
Last modified:
17/04/2026

Description

A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attackers to bypass authentication via the username parameter in index.php.