SQL Injection Vulnerability in CodeAstro Student Attendance Management System 1.0
CVE-2026-12175
Key Information:
- Vendor
Codeastro
- Vendor
- CVE Published:
- 13 June 2026
Badges
What is CVE-2026-12175?
A vulnerability in the CodeAstro Student Attendance Management System 1.0 has been identified, specifically within the function located at /attendance-php/Admin/createStudents.php. This flaw allows for SQL injection through manipulated input of the admissionNumber argument. As a result, attackers can exploit this vulnerability remotely, potentially compromising the integrity and security of the database. The details of the exploit have been made public, emphasizing the need for immediate attention and remediation by users of this system.
Affected Version(s)
Student Attendance Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
