Impact
The flaw resides in edit-apartment.php of CodeAstro Apartment Visitor Management System 1.0, where the editid parameter is concatenated into SQL statements without sanitization, enabling attackers to inject arbitrary SQL. The weakness is classified as an SQL injection under CWE‑74 and CWE‑89.
Affected Systems
Affected product is CodeAstro Apartment Visitor Management System version 1.0. The vulnerable endpoint is edit-apartment.php located under /apartment-visitor/.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in a KEV catalog. Attackers can remotely send a crafted editid value through an HTTP request to trigger the injection.
OpenCVE Enrichment