CVE-2026-14689: SQL Injection in CodeAstro Apartment Visitor Management System 1.0
CodeAstro Apartment Visitor Management System version 1.0 contains a SQL injection vulnerability in its apartment addition function. An authenticated attacker can manipulate the apartment number parameter to inject malicious SQL commands, potentially reading, modifying, or deleting database records. Proof-of-concept code is publicly available, increasing the likelihood of active exploitation.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 6.3 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Weaknesses (CWE)
- CWE-74, CWE-89
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-07-05 / 2026-07-07
NVD description (verbatim)
A security flaw has been discovered in CodeAstro Apartment Visitor Management System 1.0. The impacted element is an unknown function of the file /apartment-visitor/add-apartment.php. The manipulation of the argument apartmentno results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
6 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-14689 is a SQL injection flaw (CWE-89, CWE-74) in /apartment-visitor/add-apartment.php within CodeAstro's system. The vulnerability exists in the handling of the 'apartmentno' parameter, which is not properly sanitized before being used in database queries. The flaw requires valid user credentials (CVSS authentication requirement: PR:L) but allows unauthenticated database operations once inside. The remote, unauthenticated network vector combined with low complexity makes this exploitable by anyone with legitimate system access. Public exploit code availability significantly lowers the barrier to weaponization.
Business impact
Organizations deploying CodeAstro Apartment Visitor Management System 1.0 face data breach risk, including exposure of resident information, financial records, and tenant databases. Attackers can manipulate visitor logs, create unauthorized access records, or launch ransomware attacks following reconnaissance via database exfiltration. Operational disruption occurs if the attacker modifies or deletes critical database tables. Regulatory exposure exists if PII (resident names, contact information) is compromised under GDPR, CCPA, or local data protection laws.
Affected systems
CodeAstro Apartment Visitor Management System version 1.0 is affected. The vendor product list in the source data is empty; verify whether other CodeAstro versions or related products from the same vendor are impacted by checking the vendor's security advisory. Organizations should audit deployment across all properties or facilities using this specific version.
Exploitability
This vulnerability is readily exploitable. Proof-of-concept code is publicly disclosed, and exploitation requires only network access plus valid user credentials—a common scenario in apartment management settings where staff accounts are shared or lightly managed. The low attack complexity (AC:L) and absence of user interaction (UI:N) mean attackers can automate repeated exploitation attempts. The lack of CVSS critical impact factors reflects the authenticated requirement, but the public availability of working exploits makes active attacks likely in the near term.
Remediation
Immediately discontinue use of CodeAstro Apartment Visitor Management System 1.0 or apply vendor patches if available. Verify patched version availability by consulting the CodeAstro security advisory. Interim mitigations include: (1) restricting network access to the /apartment-visitor/add-apartment.php endpoint via firewall rules or Web Application Firewall (WAF) signatures; (2) enforcing strong password policies and multi-factor authentication for administrative and staff accounts; (3) implementing database query parameterization or prepared statements if source code access is available. Monitor database logs for anomalous query patterns indicative of SQL injection attempts.
Patch guidance
Check the CodeAstro vendor advisory for released patch versions. Verify patch availability and compatibility with your deployment before applying. If patches are unavailable, plan migration to an alternative apartment management system with demonstrated security practices. Test patches in a non-production environment first. After patching, flush any cached or compiled versions of affected scripts to ensure the updated code is loaded.
Detection guidance
Monitor for SQL injection attack patterns in application and database logs: look for unusual characters or SQL keywords (UNION, SELECT, DROP, INSERT) in the 'apartmentno' parameter within HTTP requests to /apartment-visitor/add-apartment.php. Enable database query logging and search for queries containing suspicious syntax. Configure WAF rules to block common SQL injection payloads targeting numeric parameters. Track failed database authentication attempts and privilege escalations following the patch date, as post-compromise activity may continue.
Why prioritize this
Although the CVSS score is MEDIUM (6.3), the combination of public exploits, authenticated-but-likely access (staff credentials are common), and direct database manipulation risk warrants prompt attention. The vulnerability affects core business logic (visitor access tracking) and resident data, creating legal and operational urgency. The absence of KEV status does not reduce risk; it reflects the recency of disclosure. Prioritize patching or migration within 30 days.
Risk score, explained
CVSS 6.3 reflects the requirement for authentication (PR:L), which prevents completely anonymous exploitation but does not mitigate the threat since user accounts in apartment management systems are frequently shared, poorly managed, or compromise-prone. The confidentiality, integrity, and availability impacts (C:L, I:L, A:L) are conservative; SQL injection in a database-dependent system often permits full compromise once credentials are obtained. The network vector (AV:N) and low complexity (AC:L) are significant risk multipliers. Public exploit availability elevates practical exploitability beyond the base CVSS calculation.
Frequently asked questions
Do we need to be on CodeAstro Apartment Visitor Management System 1.0 specifically to be vulnerable?
Yes, the vulnerability is specific to version 1.0. Verify your installed version by checking the system settings or vendor documentation. Earlier versions may not be affected; later patched versions should be safe if released. Contact CodeAstro support to confirm your version status and patch availability.
If we have staff accounts with strong passwords, are we protected?
No. Strong passwords reduce the risk of credential compromise, but they do not prevent SQL injection exploitation by legitimate users with account access. The vulnerability allows any authenticated user—even with limited permissions—to manipulate the apartmentno parameter to extract or modify database records. Segregate admin accounts from routine staff accounts and enforce principle of least privilege.
What data is at highest risk if this vulnerability is exploited?
Visitor logs, resident contact information, apartment assignments, financial/billing records, and access control data stored in the database are at risk. An attacker can read, modify, or delete any of this information. Prioritize backup and recovery procedures for resident and visitor databases to minimize impact.
Is this vulnerability included in CISA's Known Exploited Vulnerabilities (KEV) catalog?
No, this vulnerability is not currently on the KEV list. However, public exploit code availability means it may be added or actively exploited regardless of KEV status. Do not delay remediation based on KEV listing; treat it as actively exploitable.
This analysis is based on disclosed CVE information and vendor data current as of 2026-07-07. No exploit code is provided or endorsed. Organizations must verify patch availability and compatibility with their specific environments before applying mitigations. This document does not constitute professional security advice; consult with qualified security professionals for deployment-specific guidance. CVSS scores, vendor statements, and affected product lists may change; refer to official vendor advisories and NIST databases for authoritative information. Source: NVD (public-domain), retrieved 2026-08-13. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-10155MEDIUMSQL Injection in Bdtask Multi-Store Inventory Management System 1.0
- CVE-2026-10170MEDIUMSQL Injection in code-projects Visitor Management System 1.0
- CVE-2026-10171MEDIUMSQL Injection in code-projects Online Music Site 1.0 AdminUpdateAlbum.php
- CVE-2026-10176MEDIUMSQL Injection in Aider-AI Aider 0.86.3 Code Generation
- CVE-2026-10193MEDIUMSQL Injection in OFCMS ComnController – Authentication Required
- CVE-2026-10202MEDIUMOFCMS 1.1.3 SQL Injection in SystemDictController
- CVE-2026-10203MEDIUMSQL Injection in OFCMS 1.1.3 JSON Query Interface
- CVE-2026-10204MEDIUMSQL Injection in OFCMS 1.1.3 JSON Query Interface