PT-2026-96005 · Unknown · Qr Code Attendance Management System

·

CVE-2026-94048

·

Published

2026-09-20

·

Updated

2026-09-21

CVSS v3.1

6.6

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions CodeAstro QR Code Attendance Management System version 1.0
Description Improper privilege management exists in the Save() function within the app/Controllers/UserController.php file. A remote attacker can manipulate the role id argument to gain unauthorized privileges.
Recommendations Restrict access to the Save() function in the app/Controllers/UserController.php file or avoid using the role id argument until a fix is applied. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Privilege Assignment

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94048

Affected Products

Qr Code Attendance Management System