216.73.217.22

CVE-2026-39109

· Published 20/04/2026 18:16 · Modified 20/04/2026 19:16

Labels: CVE-2026-39109 2026-04-20CVE-2026-39109CWE-89[email protected]

Essential information

Published
20/04/2026 18:16
Modified
20/04/2026 19:16
Author
Creator
CVSS
9.4 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

CVSS metrics

Description

SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 within the username parameter of the login page (index.php). This allows an unauthenticated attacker to manipulate backend SQL queries during authentication and retrieve sensitive database contents.

NVD status

Status
Deferred — When a CVE is given this status the NVD does not plan analyze or re-analyze this CVE due to resource or other concerns.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
apartment visitors management system / apartment visitors management system cpe:2.3:a:apartment_visitors_management_system:apartment_visitors_management_system:1.1:*:*:*:*:*:*:*

References