Vulnerability Description
SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 within the username parameter of the login page (index.php). This allows an unauthenticated attacker to manipulate backend SQL queries during authentication and retrieve sensitive database contents.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/efekaanakkar/Apartment-Visitors-Management-System-CVEs/
- https://phpgurukul.com/?sdm_process_download=1&download_id=21524
- https://phpgurukul.com/apartment-visitors-management-system-using-php-and-mysql/
FAQ
What is CVE-2026-39109?
CVE-2026-39109 is a vulnerability with a CVSS score of 9.4 (CRITICAL). SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 within the username parameter of the login page (index.php). This allows an unauthenticate...
How severe is CVE-2026-39109?
CVE-2026-39109 has been rated CRITICAL with a CVSS base score of 9.4/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-39109?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.