CVE-2026-39109 - Vulnerability Analysis
CriticalCVSS: 9.4Last Updated: April 20, 2026
Apartment Visitors Management System - SQL Injection
Overview
Apartment Visitors Management System V1.1 contains a sql injection caused by unsanitized input in the username parameter of the login page (index.php), letting unauthenticated attackers retrieve sensitive database contents.
Severity & Score
Impact
Unauthenticated attackers can retrieve sensitive database contents, potentially compromising the entire database.
Mitigation
Update to the latest version of Apartment Visitors Management System.
References
Social Media Activity(2 posts)
š“ CVE-2026-39109 - Critical (9.4) SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 within the username parameter of the login page (index.php). This allows an unauthenticated attacker to manipulate backend SQL queries du... š https://www.thehackerwire.com/vulnerability/CVE-2026-39109/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postš“ CVE-2026-39109 - Critical (9.4) SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 within the username parameter of the login page (index.php). This allows an unauthenticated attacker to manipulate backend SQL queries du... š https://www.thehackerwire.com/vulnerability/CVE-2026-39109/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postRelated Resources
Details
- CVE ID
- CVE-2026-39109
- Severity
- Critical
- CVSS Score
- 9.4
- Type
- sql_injection
- Status
- rejected
- EPSS
- 0.0%
- Social Posts
- 2
CWE
- CWE-89
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L