Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 20 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0. This affects the function Save of the file app/Controllers/UserController.php. The manipulation of the argument role_id results in improper privilege management. The attack can be executed remotely. The exploit is now public and may be used. | |
| Title | CodeAstro QR Code Attendance Management System UserController.php save privileges management | |
| First Time appeared |
Codeastro
Codeastro qr Code Attendance Management System |
|
| Weaknesses | CWE-266 CWE-269 |
|
| CPEs | cpe:2.3:a:codeastro:qr_code_attendance_management_system:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Codeastro
Codeastro qr Code Attendance Management System |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-20T19:15:08.082Z
Reserved: 2026-09-19T21:46:53.131Z
Link: CVE-2026-94048
No data.
No data.
No data.
OpenCVE Enrichment
No data.