Critical SQL Injection Vulnerability in CodeAstro Attendance System (CVE-2026-37749)
ID: 5446e55c-b14b-5075-8c72-00c4ad59f82a
STIX ID: report--5446e55c-b14b-5075-8c72-00c4ad59f82a
Feed Name: ThreatCluster
Threat Score
A critical SQL injection (CVE-2026-37749) in CodeAstro Simple Attendance Management System v1.0 enables remote unauthenticated attackers to bypass authentication through the username parameter in index.php, potentially exposing sensitive attendance records; a proof-of-concept is available, the CVSS is reported as 9.8, and immediate patching or network access restriction is advised (published April 17, 2026).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
