Ghostwire

CVE-2026-39112: Cross Site Scripting vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in...

MEDIUM CVSS 5.5

Published: April 20, 2026 | Last Modified: April 20, 2026

Description

Cross Site Scripting vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the visname parameter of visitors-form.php. An authenticated attacker can inject arbitrary JavaScript that is later executed when the malicious input is viewed in manage-newvisitors.php or visitor-detail.php.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (2 articles)

References