Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the username parameter at index.php.
https://github.com/rickxy/Student-Attendance-Management-System
https://gist.github.com/celbahraoui/b9437dbec7ab539531fe44f0c26b48a2