Vulnerability Description
SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the email parameter of the forgot password page (forgot-password.php). This allows an unauthenticated attacker to manipulate backend SQL queries and retrieve sensitive user data.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/efekaanakkar/Apartment-Visitors-Management-System-CVEs/
- https://phpgurukul.com/?sdm_process_download=1&download_id=21524
- https://phpgurukul.com/apartment-visitors-management-system-using-php-and-mysql/
FAQ
What is CVE-2026-39111?
CVE-2026-39111 is a vulnerability with a CVSS score of 7.5 (HIGH). SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the email parameter of the forgot password page (forgot-password.php). This allows an u...
How severe is CVE-2026-39111?
CVE-2026-39111 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-39111?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.