← back
CVE-2025-11599

Campcodes Online Apartment Visitor Management System forgot-password.php sql injection

CVSS 6.9 MEDIUMEPSS 0.4%CWE-74CWE-89
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.9EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
11 Oct 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A weakness has been identified in Campcodes Online Apartment Visitor Management System 1.0. This impacts an unknown function of the file /forgot-password.php. This manipulation of the argument email causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →