Description
A vulnerability was determined in CodeAstro Student Attendance Management System 1.0. Affected is an unknown function of the file /attendance-php/Admin/createClassArms.php. This manipulation of the argument classId causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Problem types
Product status
Timeline
| 2026-06-08: | Advisory disclosed |
| 2026-06-08: | VulDB entry created |
| 2026-06-08: | VulDB entry last update |
Credits
SchneiderGrace (VulDB User)
References
vuldb.com/vuln/369182 (VDB-369182 | CodeAstro Student Attendance Management System createClassArms.php sql injection)
vuldb.com/vuln/369182/cti (VDB-369182 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/cve/CVE-2026-11585 (CVE-2026-11585 | CVE Analysis and Report)
vuldb.com/submit/836800 (Submit #836800 | codeastro Student Attendance Management System V1.0 SQL Injection)
github.com/Andelstander/cve/issues/10
codeastro.com/