


Perceptive Security
SOC/SIEM Consultancy

A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attackers to bypass authentication via the use…
Published:
16 April 2026 at 22:00:00
Alert date:
17 April 2026 at 17:01:02
Source:
nvd.nist.gov
Web Technologies, Database & Storage
A SQL injection vulnerability exists in CodeAstro Simple Attendance Management System v1.0 that allows remote unauthenticated attackers to bypass authentication. The vulnerability is located in the username parameter of the index.php file. Attackers can exploit this flaw without authentication to gain unauthorized access to the system. This represents a critical security issue as it allows complete authentication bypass through SQL injection techniques.
Technical details
Mitigation steps:
Affected products:
CodeAstro Simple Attendance Management System
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-37749
https://codeastro.com/simple-attendance-management-system-in-php-with-source-code/
https://github.com/menevarad007/CVE-2026-37749
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
