Executive brief
A vulnerability exists in the code-projects Visitor Management System, a software used to track and manage guest access to facilities. An attacker can exploit this flaw to interfere with the application's database, potentially leading to unauthorized access to visitor records or the ability to modify system data. In some scenarios, this could be used as part of a larger attack to take full control of the server.
Technical details
A SQL injection vulnerability exists in code-projects Visitor Management System 1.0 within the /vms/php/phone_0.php file. The issue stems from improper neutralization of special elements used in an SQL command via the 'phone' argument. A remote attacker with low privileges can exploit this vulnerability to execute arbitrary SQL commands against the backend database. Public exploit code suggests this vulnerability can be chained to achieve Remote Code Execution (RCE). As of the advisory date, no official patch has been confirmed.
Affected products
- code-projects Visitor Management System 1.0
Timeline
- 2026-05-31: disclosed
- 2026-05-31: advisory