Loading market data...
← Back to CVE feed

CVE-2026-39109

CRITICAL CVSS 9.4 View on NVD ↗

Description

SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 within the username parameter of the login page (index.php). This allows an unauthenticated attacker to manipulate backend SQL queries during authentication and retrieve sensitive database contents.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Published: Apr 20, 2026 18:16 UTC Modified: Apr 20, 2026 19:16 UTC