PT-2025-32291 · Unknown · Attendance Management System

Published

2025-08-07

·

Updated

2025-08-12

·

CVE-2023-41523

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Student Attendance Management System version 1
Description The Student Attendance Management System is susceptible to a SQL injection issue through the emailAddress parameter at the createClassTeacher.php endpoint.
Recommendations As a temporary workaround, consider restricting access to the createClassTeacher.php endpoint to minimize the risk of exploitation. Sanitize the emailAddress parameter before using it in any SQL queries.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2023-41523

Affected Products

Attendance Management System