A SQL injection vulnerability in CodeAstro Simple...
Critical severity
Unreviewed
Published
Apr 17, 2026
to the GitHub Advisory Database
•
Updated Apr 17, 2026
Description
Published by the National Vulnerability Database
Apr 17, 2026
Published to the GitHub Advisory Database
Apr 17, 2026
Last updated
Apr 17, 2026
A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attackers to bypass authentication via the username parameter in index.php.
References