{"id":"CVE-2026-94048","published":"2026-09-20T20:16:54.510","lastModified":"2026-09-21T20:17:40.200","description":"A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0. This affects the function Save of the file app/Controllers/UserController.php. The manipulation of the argument role_id results in improper privilege management. The attack can be executed remotely. The exploit is now public and may be used.","cvssScore":6.6,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L","cwes":["CWE-266","CWE-269"],"vendors":[],"products":[],"references":[{"url":"https://codeastro.com/","tags":[]},{"url":"https://github.com/Witiers/CVEs/issues/4","tags":[]},{"url":"https://vuldb.com/cve/CVE-2026-94048","tags":[]},{"url":"https://vuldb.com/submit/949593","tags":[]},{"url":"https://vuldb.com/vuln/407977","tags":[]},{"url":"https://vuldb.com/vuln/407977/cti","tags":[]}],"exploitRefs":[{"url":"https://github.com/Witiers/CVEs/issues/4","tags":[]}],"hasPoc":true,"ai":null}