Unrated severityNVD Advisory· Published Jul 6, 2026· Updated Jul 6, 2026
CodeAstro Apartment Visitor Management System report.php sql injection
CVE-2026-14796
Description
A vulnerability was found in CodeAstro Apartment Visitor Management System 1.0. This affects an unknown part of the file /apartment-visitor/report.php. Performing a manipulation of the argument fromdate results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
Patches
Vulnerability mechanics
References
6- github.com/lilukun337/cve/issues/7mitreexploitissue-tracking
- vuldb.com/cve/CVE-2026-14796mitrethird-party-advisory
- vuldb.com/submit/850849mitrethird-party-advisory
- codeastro.commitreproduct
- vuldb.com/vuln/376390mitrevdb-entrytechnical-description
- vuldb.com/vuln/376390/ctimitresignaturepermissions-required
News mentions
0No linked articles in our index yet.