Codeastro · Apartment Visitor Management System · CVE-2026-14766
**Name of the Vulnerable Software and Affected Versions**
CodeAstro Apartment Visitor Management System version 1.0
**Description**
An issue exists in the POST Parameter Handler component within the file `/apartment-visitor/search-result.php`. The manipulation of the `searchdata` parameter allows for remote SQL injection, a technique where malicious SQL statements are inserted into entry fields for execution.
**Recommendations**
As a temporary workaround, avoid using the `searchdata` parameter in the `/apartment-visitor/search-result.php` endpoint until a fix is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.