CVE-2026-14766: Codeastro Apartment Visitor Management System
Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.
A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. Affected by this issue is some unknown functionality of the file /apartment-visitor/search-result.php of the component POST Parameter Handler. The manipulation of the argument searchdata leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Affected products
- Codeastro Apartment Visitor Management System: version 1.0 only
Published 2026-07-05. Last modified 2026-07-06.