Impact
An unknown function in the add-apartment.php script of CodeAstro Apartment Visitor Management System 1.0 reads the apartmentno parameter without proper validation, allowing an attacker to inject malicious SQL statements. This flaw can lead to unauthorized data modification or disclosure through query manipulation. The description indicates the attack can be launched remotely, and an exploit has already been made public.
Affected Systems
The only affected product listed by the CNA is CodeAstro Apartment Visitor Management System version 1.0. No other variants or versions are mentioned in the data.
Risk and Exploitability
The CVSS score of 5.3 reflects moderate severity, while the EPSS score of less than 1% points to a very low likelihood of widespread exploitation today. The vulnerability is not listed in the CISA KEV catalog, yet the publicly released exploit raises the possibility of targeted attacks. Based on the description, the likely attack vector is an HTTP request to the vulnerable /apartment-visitor/add-apartment.php endpoint, where an attacker supplies a crafted apartmentno value to execute unwanted SQL commands.
OpenCVE Enrichment