PT-2026-33819 · Unknown · Apartment Visitor Management System

Published

2026-04-20

·

Updated

2026-04-21

·

CVE-2026-39112

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apartment Visitors Management System version 1.1
Description Cross Site Scripting occurs in the 'visitors-form.php' endpoint via the visname parameter. An authenticated attacker can inject arbitrary JavaScript, which is subsequently executed when the malicious input is viewed in 'manage-newvisitors.php' or 'visitor-detail.php'.
Recommendations As a temporary workaround, avoid using the visname parameter in the 'visitors-form.php' endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-39112

Affected Products

Apartment Visitor Management System