Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/menevarad007/cve-2026-37749
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityAuthentication
GitHubmenevarad007/cve-2026-37749

CVE-2026-37749

Proof-of-concept for SQL injection in CodeAstro Simple Attendance Management System 1.0, demonstrating authentication bypass via crafted username payload.

View Repository
1585 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-37749 — CodeAstro Simple Attendance Management System 1.0 - SQL Injection

Details

FieldInfo
CVE IDCVE-2026-37749
TypeSQL Injection → Authentication Bypass
SeverityCritical (CVSSv3: 9.8)
VendorCodeAstro
ProductSimple Attendance Management System
Version1.0
DiscovererVarad AP Mene
Date2026-04-16
CWECWE-89

Description

A SQL Injection vulnerability exists in CodeAstro Simple Attendance Management System v1.0 in the login form of index.php. The username POST parameter is concatenated directly into a MySQL query without sanitization or use of prepared statements. An unauthenticated remote attacker can bypass authentication and gain administrative access by submitting a crafted SQL payload in the username field.

Affected Product: Simple Attendance Management System v1.0 Vendor: CodeAstro Affected File: index.php Parameter: username (POST) Payload: admin'-- - CVE: CVE-2026-37749 CWE: CWE-89 CVSSv3: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)


Product Description

Simple Attendance Management System 1.0 is a PHP/MySQL web application published by CodeAstro used to manage student attendance records in schools and colleges.

Vendor URL: https://codeastro.com/simple-attendance-management-system-in-php-with-source-code/


Vulnerable File

index.php — Login form


Vulnerable Code

// index.php - Line 23
$query = "SELECT * FROM admin WHERE username='$username' AND password='$password'";
$result = mysql_query($query);

Raw $_POST data used directly — no escaping, no prepared statements.


Proof of Concept

Step 1 — Go to login page: http://target/attendance/index.php

Step 2 — Enter these credentials: Username: admin'-- - Password: anything Type: admin

Step 3 — Click Login Result: Admin panel access granted without valid credentials!


Impact

  • Authentication bypass without valid credentials
  • Full admin access to all attendance records
  • Data exposure and manipulation
  • No authentication required — exploitable by anyone

Remediation

$stmt = $mysqli->prepare("SELECT * FROM admin WHERE username=? AND password=?");
$stmt->bind_param("ss", $username, $password);
$stmt->execute();
$result = $stmt->get_result();

Timeline

DateEvent
2026-03-24Vulnerability discovered
2026-03-24Reported to MITRE
2026-04-16CVE-2026-37749 assigned
2026-04-16Public disclosure
2026-04-16MITRE notified about publication
2026-04-16Vendor notified via CodeAstro contact form
2026-04-16Submitted to Exploit-DB

References

  • https://codeastro.com/simple-attendance-management-system-in-php-with-source-code/

Discoverer

Varad AP Mene

  • Email: [email protected]
  • GitHub: https://github.com/menevarad007
Download Tool