CVE-2026-77019: CodeAstro Apartment Visitor Management System forgotpw.php sql injection
A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. Affected is an unknown function of the file /apartment-visitor/forgotpw.php. Executing a manipulation of the argument secode can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack can be launched remotely and requires no privileges or user interaction according to the supplied vector. An attacker manipulates the secode argument handled by /apartment-visitor/forgotpw.php.
Which deployments are known to be affected?
The affected product is CodeAstro Apartment Visitor Management System version 1.0. The provided data does not establish whether other versions or default installations are affected.
Is exploitation likely to be practical?
A public exploit has been disclosed and may be used. The supplied rating characterizes attack complexity as low.