MEDIUM
CVE-2026-94048
CVSS
6.6
Description
A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0. This affects the function Save of the file app/Controllers/UserController.php. The manipulation of the argument role_id results in improper privilege management. The attack can be executed remotely. The exploit is now public and may be used.
Weakness (CWE)
CWE-266
Incorrect Privilege Assignment
CWE-269
Improper Privilege Management
EPSS Score
0.23%
Probability of exploitation in next 30 days
13.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.