PT-2026-47444 · Unknown · Codeastro Student Attendance Management System

·

CVE-2026-11583

·

Published

2026-06-08

·

Updated

2026-06-08

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CodeAstro Student Attendance Management System version 1.0
Description SQL injection can be triggered remotely via the manipulation of the className argument within the '/attendance-php/Admin/createClass.php' endpoint. SQL injection is a type of flaw that allows an attacker to interfere with the queries that an application makes to its database.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11583

Affected Products

Codeastro Student Attendance Management System