CVE-2026-39111Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the email parameter of the forgot password page (forgot-password.php). This allows an unauthenticated attacker to manipulate backend SQL queries and retrieve sensitive user data.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-21); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-21: 2Mentions · 2026-04-22: 1Patch / Workaround · 2026-04-22: 1Technical Details · 2026-04-21: 2Technical Details · 2026-04-22: 104-2104-22
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-212
Disclosure2
2026-04-221
Patch1
Full discourse3 posts
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 HIGH: CVE-2026-39111 (CVSS 7.5) - SQL Injection in Apartment Visitors Management System v1.1. Unauthenticated attackers can extract sensitive user data via forgot-password[.]php. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/W1JaqdxHWH

    Post summary

    The tweet discloses a high‑severity SQL injection vulnerability and urges users to apply a patch immediately.

    0000148
    26 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-39111 SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the email parameter of the forgot password page (forg… https://www.cve.org/CVERecord?id=CVE-2026-39111 ----- Traducción: CVE-2026-39111 Vul… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-39111, an SQL injection flaw in the email parameter on the forgot password page of Apartment Visitors Management System V1.1, and provides a link to the official CVE record, but offers no PoC, exploit details, patch information, or evidence of active exploitation.

    0000027
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-39111 SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the email parameter of the forgot password page (forg… https://www.cve.org/CVERecord?id=CVE-2026-39111

    Post summary

    The CVE-2026-39111 describes a SQL Injection flaw in the forgot password email field of Apartment Visitors Management System V1.1, with details provided but no PoC, exploit, or patch referenced.

    00000143
    57.2K followersView on X

Explore more