Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the emailAddress parameter at createClassTeacher.php.
https://github.com/rickxy/Student-Attendance-Management-System
https://gist.github.com/celbahraoui/b18580d4acf3e4ada6c220c7416469ed