VYPR
Medium severity6.6NVD Advisory· Published Sep 20, 2026

CVE-2026-94048

CVE-2026-94048

Description

A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0. This affects the function Save of the file app/Controllers/UserController.php. The manipulation of the argument role_id results in improper privilege management. The attack can be executed remotely. The exploit is now public and may be used.

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.