CVE-2026-39112 Details
Description
Cross Site Scripting vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the visname parameter of visitors-form.php. An authenticated attacker can inject arbitrary JavaScript that is later executed when the malicious input is viewed in manage-newvisitors.php or visitor-detail.php.
A stored cross-site scripting vulnerability has been identified in the Apartment Visitors Management System, version 1.1. The issue resides in the 'visname' parameter of 'visitors-form.php'. An authenticated attacker can inject arbitrary JavaScript, which is executed when the malicious input is viewed in 'manage-newvisitors.php' or 'visitor-detail.php'.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 20, 2026CISA-ADP
Assessed Apr 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/efekaanakkar/Apartment-Visitors-Management-System-CVEs/ | [email protected] | BundleExploitTechnical Description |
| https://phpgurukul.com/apartment-visitors-management-system-using-php-and-mysql/ | [email protected] | ProductVendor |
| https://phpgurukul.com/?sdm_process_download=1&download_id=21524 | [email protected] | Broken LinkProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Apartment Visitors Management System | 1.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 20, 2026 | New CVE Received | [email protected] |
| Apr 20, 2026 | CVE Modified | CISA-ADP |
Volerion