


Perceptive Security
SOC/SIEM Consultancy

SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the email parameter of the forgot password page…
Published:
19 april 2026 om 22:00:00
Alert date:
20 april 2026 om 19:02:30
Source:
nvd.nist.gov
Web Technologies, Database & Storage
SQL injection vulnerability discovered in Apartment Visitors Management System V1.1 affecting the email parameter on the forgot password page (forgot-password.php). The vulnerability allows unauthenticated attackers to manipulate backend SQL queries and retrieve sensitive user data. The flaw is located in a common authentication bypass scenario where password reset functionality lacks proper input validation. This represents a critical security issue as it requires no authentication and can lead to data exfiltration.
Technical details
Mitigation steps:
Affected products:
Apartment Visitors Management System
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-39111
https://github.com/efekaanakkar/Apartment-Visitors-Management-System-CVEs/
https://phpgurukul.com/?sdm_process_download=1&download_id=21524
https://phpgurukul.com/apartment-visitors-management-system-using-php-and-mysql/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
