CVE-2026-14689: CodeAstro Apartment Visitor Management System add-apartment.php sql injection
A security flaw has been discovered in CodeAstro Apartment Visitor Management System 1.0. The impacted element is an unknown function of the file /apartment-visitor/add-apartment.php. The manipulation of the argument apartmentno results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14689?
CVE-2026-14689 has a medium severity rating of 6.3.
How do I fix CVE-2026-14689?
To fix CVE-2026-14689, sanitize and validate the input for the apartmentno parameter to prevent SQL injection.
Can CVE-2026-14689 be exploited remotely?
Yes, CVE-2026-14689 can be exploited remotely due to the nature of the vulnerability.
What type of vulnerability is CVE-2026-14689?
CVE-2026-14689 is an SQL Injection vulnerability that affects the CodeAstro Apartment Visitor Management System.
What is the affected software version for CVE-2026-14689?
CVE-2026-14689 affects CodeAstro Apartment Visitor Management System version 1.0.