CVE-2026-37749
CRITICAL SEVERITYCVSS Score & Metrics
Base Score
9.8 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Description
A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attackers to bypass authentication via the username parameter in index.php.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-89
Source
NVD
Discussion (0)
Add Comment
No comments yet. Be the first!