CVE-2026-14640: CodeAstro Apartment Visitor Management System Login index.php sql injection
A vulnerability was found in CodeAstro Apartment Visitor Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipulation of the argument Username results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14640?
The severity of CVE-2026-14640 is rated as high with a score of 7.3.
What type of vulnerability is CVE-2026-14640?
CVE-2026-14640 is an SQL injection vulnerability found in the Login component of the CodeAstro Apartment Visitor Management System.
How do I fix CVE-2026-14640?
To fix CVE-2026-14640, you should sanitize and validate user inputs to prevent SQL injection attacks.
Can CVE-2026-14640 be exploited remotely?
Yes, CVE-2026-14640 can be exploited remotely by manipulating the Username argument in the Login function.
What component of CodeAstro is affected by CVE-2026-14640?
CVE-2026-14640 affects the Login component in the index.php file of the CodeAstro Apartment Visitor Management System.