Impact
A flaw is present in the visitor-entry.php module where the visname argument is passed unchecked to a database query. This oversight enables an attacker to inject arbitrary SQL statements when crafting requests to that endpoint. The injection is performed over the web, and the exploit code is publicly available, meaning remote attackers can invoke it without local or privileged access.
Affected Systems
The affected product is CodeAstro’s Apartment Visitor Management System version 1.0, specifically its visitor-entry.php page that processes the visname field.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.3, indicating moderate severity, and an EPSS score of less than 1 %, suggesting a low likelihood of widespread exploitation at present. It is not included in the CISA KEV catalog. Because the injection can be triggered remotely via the web interface, an external attacker only needs internet connectivity to the application and no special local privileges.
OpenCVE Enrichment