Description

SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the contactno parameter of the forgot password page (forgot-password.php). This allows an unauthenticated attacker to manipulate backend SQL queries during authentication and retrieve sensitive database contents.

INFO

Published Date :

2026-04-20T00:00:00.000Z

Last Modified :

2026-04-20T18:34:55.729Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2026-39110 vulnerability.

No data.

CVSS Vulnerability Scoring System