CVE-2026-14796: CodeAstro Apartment Visitor Management System report.php sql injection
A vulnerability was found in CodeAstro Apartment Visitor Management System 1.0. This affects an unknown part of the file /apartment-visitor/report.php. Performing a manipulation of the argument fromdate results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14796?
The severity of CVE-2026-14796 is medium with a score of 6.3.
How do I fix CVE-2026-14796?
To fix CVE-2026-14796, you should validate and sanitize user input in the 'fromdate' argument before processing it in SQL queries.
What type of vulnerability is CVE-2026-14796?
CVE-2026-14796 is a SQL Injection vulnerability affecting the CodeAstro Apartment Visitor Management System.
Can CVE-2026-14796 be exploited remotely?
Yes, CVE-2026-14796 can be exploited remotely by manipulating the 'fromdate' argument.
Which file is affected by CVE-2026-14796?
CVE-2026-14796 affects the file /apartment-visitor/report.php in the CodeAstro Apartment Visitor Management System.