MEDIUM

CVE-2026-94048

2026-09-20 CVSS v3.1
CVSS
6.6

Description

A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0. This affects the function Save of the file app/Controllers/UserController.php. The manipulation of the argument role_id results in improper privilege management. The attack can be executed remotely. The exploit is now public and may be used.

Weakness (CWE)

CWE-266 Incorrect Privilege Assignment
CWE-269 Improper Privilege Management

EPSS Score

0.23%
Probability of exploitation in next 30 days
13.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE