Unknown · Attendance Management System · CVE-2021-44280
**Name of the Vulnerable Software and Affected Versions**
Attendance Management System version 1.0
**Description**
The issue is related to a SQL injection vulnerability in the `makeSafe` function located in `admin/incFunctions.php`. This vulnerability can be exploited by a remote attacker to impact the confidentiality, integrity, and availability of protected information. The vulnerability is due to the lack of protection of the SQL query structure.
**Recommendations**
For Attendance Management System version 1.0, as a temporary workaround, consider disabling the `makeSafe` function until a patch is available. Restrict access to the `admin/incFunctions.php` file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.