
CVE-2025-3143 – SourceCodester Apartment Visitor Management System visitor-entry.php sql injection
https://notcve.org/view.php?id=CVE-2025-3143
03 Apr 2025 — A vulnerability classified as critical has been found in SourceCodester Apartment Visitor Management System 1.0. Affected is an unknown function of the file /visitor-entry.php. The manipulation of the argument visname/address leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/Lena-lyy/SQL/blob/main/SQL4.md • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2025-3142 – SourceCodester Apartment Visitor Management System add-apartment.php sql injection
https://notcve.org/view.php?id=CVE-2025-3142
03 Apr 2025 — A vulnerability was found in SourceCodester Apartment Visitor Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /add-apartment.php. The manipulation of the argument buildingno leads to sql injection. The attack may be initiated remotely. • https://github.com/Lena-lyy/SQL/blob/main/SQL3.md • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2025-3045 – oretnom23/SourceCodester Apartment Visitor Management System remove-apartment.php sql injection
https://notcve.org/view.php?id=CVE-2025-3045
01 Apr 2025 — A vulnerability, which was classified as critical, was found in oretnom23/SourceCodester Apartment Visitor Management System 1.0. Affected is an unknown function of the file /remove-apartment.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/byxs0x0/SQL/blob/main/SQL2.md • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2022-38265
https://notcve.org/view.php?id=CVE-2022-38265
08 Sep 2022 — Apartment Visitor Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter at /avms/edit-apartment.php. Se ha detectado que Apartment Visitor Management System versión v1.0, contiene una vulnerabilidad de inyección SQL por medio del parámetro editid en el archivo /avms/edit-apartment.php • https://github.com/xxxcoll/bug_report/blob/main/vendors/oretnom23/apartment-visitor-management-system/SQLi-1.md • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •