CVE-2026-94048: CodeAstro QR Code Attendance Management System UserController.php save privileges management

Published Sep 20, 2026
·
Updated

A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0. This affects the function Save of the file app/Controllers/UserController.php. The manipulation of the argument roleid results in improper privilege management. The attack can be executed remotely. The exploit is now public and may be used.

Affected Software

1 affected component
Codeastro QR Code Attendance Management System=1.0

Event History

Sep 20, 2026
CVE Published
via MITRE·07:15 PM
Data Sourced
via MITRE·07:15 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs high privileges (PR:H) to manipulate the role_id argument in the Save function. Exploitation can be performed remotely and does not require user interaction.

2

What is the likely impact of successful exploitation?

The issue causes improper privilege management and may allow changes to user role assignments. The reported impact includes low confidentiality, integrity, and availability effects, with scope changed (S:C).

3

Is public exploit code available?

Yes. The exploit is reported as public and may be used, increasing the likelihood of exploitation where an attacker has the required privileges.

4

Which component should be reviewed for exposure?

Review CodeAstro QR Code Attendance Management System version 1.0, specifically app/Controllers/UserController.php and its Save function. Check whether role_id can be supplied or altered during user save operations.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203