CVE-2026-14797: CodeAstro Apartment Visitor Management System edit-apartment.php sql injection
A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. This vulnerability affects unknown code of the file /apartment-visitor/edit-apartment.php. Executing a manipulation of the argument editid can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14797?
The severity of CVE-2026-14797 is rated as medium with a score of 6.3.
How do I fix CVE-2026-14797?
To fix CVE-2026-14797, sanitize and validate input parameters used in the edit-apartment.php file to prevent SQL injection.
What type of vulnerability is CVE-2026-14797?
CVE-2026-14797 is an SQL injection vulnerability affecting the CodeAstro Apartment Visitor Management System.
Can CVE-2026-14797 be exploited remotely?
Yes, CVE-2026-14797 can be exploited remotely by manipulating the argument editid in the vulnerable script.
What version of CodeAstro is affected by CVE-2026-14797?
CVE-2026-14797 affects version 1.0 of the CodeAstro Apartment Visitor Management System.