CVE-2026-11582: CodeAstro Student Attendance Management System index.php sql injection

Published Jun 8, 2026
·
Updated

A flaw has been found in CodeAstro Student Attendance Management System 1.0. The impacted element is an unknown function of the file /attendance-php/index.php. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used.

Affected Software

1 affected component
Codeastro CodeAstro Student Attendance Management System=1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove CodeAstro Student Attendance Management System 1.0 from your environment.

    If the application is not required or cannot be adequately mitigated, uninstall or remove the CodeAstro Student Attendance Management System 1.0 (or disable the attendance module) until an official fix is released.

  2. Configuration

    Disable or restrict access to the /attendance-php/index.php endpoint (for example via web server ACLs, virtual host configuration, or application configuration) until a secure code-level fix is available.

    CodeAstro Student Attendance Management System access to /attendance-php/index.php = restricted or disabled
  3. Compensating control

    Apply a web application firewall (WAF) or IPS rule to block SQL injection attempts targeting the Username parameter and the /attendance-php/index.php endpoint. If a WAF is not available, restrict access to the application (or that endpoint) at the network perimeter to trusted IP addresses only.

  4. Operational

    Assume potential exploitation (exploit published). Review web and application logs for suspicious activity targeting the Username parameter or /attendance-php/index.php, rotate any credentials or secrets that may have been exposed, and restore affected systems from known-good backups if compromise is detected.

Event History

Jun 8, 2026
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-11582?

The severity of CVE-2026-11582 is medium, rated at 5.5.

2

How can I fix CVE-2026-11582?

To fix CVE-2026-11582, ensure to validate and sanitize user inputs in the index.php file to prevent SQL injection.

3

What type of vulnerability is found in CVE-2026-11582?

CVE-2026-11582 is an SQL injection vulnerability that allows attackers to manipulate database queries.

4

Can CVE-2026-11582 be exploited remotely?

Yes, CVE-2026-11582 can be exploited remotely by manipulating the Username argument in the affected system.

5

What is the risk rating for CVE-2026-11582?

The risk rating for CVE-2026-11582 is 52, indicating a moderate risk concern.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203