Junglewise Threat Intelligence

CVE-2026-14796: CodeAstro Apartment Visitor Management System SQL injection in report.php

CVE-2026-14796 · Severity: medium · CVSS 6.3 · Published 2026-07-06

Technologies: CodeAstro Apartment Visitor Management System. Vendors: CodeAstro.

Executive brief

The CodeAstro Apartment Visitor Management System, a web application used to track and manage visitors in residential complexes, contains a security flaw in its reporting feature. An attacker can exploit this to gain unauthorized access to the underlying database, potentially leading to the exposure of sensitive visitor logs or resident information. This could result in data theft, unauthorized modification of records, or disruption of the management system's operations.

Technical details

A SQL injection vulnerability exists in CodeAstro Apartment Visitor Management System 1.0 within the /apartment-visitor/report.php file. The issue stems from improper neutralization of the 'fromdate' POST parameter before it is used in a database query. A remote attacker with low privileges can provide a specially crafted date string (e.g., using time-based blind payloads) to execute arbitrary SQL commands. This can lead to unauthorized data retrieval, modification, or deletion. A public exploit (PoC) using sqlmap has been disclosed, though no official patch is currently confirmed.

Affected products

  • CodeAstro Apartment Visitor Management System 1.0

Timeline

  • 2026-06-07: disclosed: Initial disclosure on GitHub by lilukun337/cve/issues/7
  • 2026-07-06: advisory: NVD publication date

References

Related threats