Impact
The CodeAstro Apartment Visitor Management System contains a flaw in the report.php script that allows an attacker to manipulate the fromdate parameter to inject arbitrary SQL. This is a classic SQL injection vulnerability that can be exploited to read or alter the underlying database. The vulnerability is classified under CWE‑74 and CWE‑89 and has been publicly disclosed. Replication of the attack requires no local privileges and can be performed over the network by sending specially crafted HTTP requests.
Affected Systems
The affected product is CodeAstro:Apartment Visitor Management System 1.0. The flaw resides in the /apartment-visitor/report.php component. No other affected versions are currently listed.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk to confidentiality and integrity. The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. However, because the attack can be performed remotely by manipulating a public‑facing parameter, organizations running this system should treat the risk as moderate and address it promptly. The most likely attack vector involves sending directed HTTP requests to the report.php endpoint from a remote host.
OpenCVE Enrichment