Impact
Swapping the email argument in password‑recovery.php allows an unauthenticated user to inject arbitrary SQL, potentially exposing or altering all data in the underlying database. This injection can be triggered remotely by sending a crafted request to the affected script, and an exploit is publicly available, escalating the risk to active exploitation.
Affected Systems
CodeAstro Apartment Visitor Management System version 1.0 is affected. No other product versions are documented as vulnerable.
Risk and Exploitability
The CVSS score of 6.9 reflects a moderate severity risk. An attacker can reach the vulnerable endpoint without authentication, making exploitation straightforward. The EPSS score is not provided, so the precise likelihood is unclear, but the public availability of exploit code suggests a realistic threat. The vulnerability is not yet listed in the CISA KEV catalog.
OpenCVE Enrichment