Impact
The flaw in CodeAstro Apartment Visitor Management System, located in the Username field of the /index.php login page, allows injection of arbitrary SQL commands. This is a SQL injection. According to the CVE description, this injection can be triggered from a remote network and a public exploit confirms that the flaw is usable by attackers.
Affected Systems
The vulnerability affects CodeAstro’s Apartment Visitor Management System version Login component accessed through /index.php. No other versions or configurations are currently identified as impacted.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity while the EPSS score of <1% suggests a very low probability of exploitation, though still non-zero. The issue is not listed in CISA’s KEV catalog, and the provided description indicates that the attack can be performed over the network without any special privileges being required.
OpenCVE Enrichment