CVE-2026-77020

Summary

A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file password-recovery.php. The manipulation of the argument email leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

Affected Software

VendorProductVersion RangeStatus
CodeAstroApartment Visitor Management System1.0affected

Weaknesses

  • CWE-89: SQL Injection
  • CWE-74: Injection

References