Impact
The vulnerability is an SQL injection flaw in the POST parameter handler of /apartment-visitor/search-result.php. By altering the searchdata argument, an attacker can execute arbitrary SQL statements against the system database, allowing modification, deletion, or exfiltration of data and compromising confidentiality and integrity.
Affected Systems
CodeAstro Apartment Visitor Management System version 1.0. No additional version details are available in the CNA data.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score is <1%, showing that exploitation is unlikely in the wild. The CVE is not listed in CISA’s KEV catalog. Remote attackers can exploit the SQL injection by crafting a POST request to search-result.php, which could lead to unauthorized data modification or exfiltration if successful.
OpenCVE Enrichment