A weakness has been identified in Campcodes Online Apartment Visitor Management System 1.0. This impacts an unknown function of the file /forgot-password.php. This manipulation of the argument email causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/feiyang85/cve/issues/1 | Exploit Third Party Advisory Issue Tracking | 
| https://vuldb.com/?ctiid.327920 | Permissions Required VDB Entry | 
| https://vuldb.com/?id.327920 | Third Party Advisory VDB Entry | 
| https://vuldb.com/?submit.671910 | Third Party Advisory VDB Entry | 
| https://www.campcodes.com/ | Product | 
| https://github.com/feiyang85/cve/issues/1 | Exploit Third Party Advisory Issue Tracking | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    20 Oct 2025, 18:19
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time | Campcodes Campcodes online Apartment Visitor Management System | |
| CPE | cpe:2.3:a:campcodes:online_apartment_visitor_management_system:1.0:*:*:*:*:*:*:* | |
| References | () https://github.com/feiyang85/cve/issues/1 - Exploit, Third Party Advisory, Issue Tracking | |
| References | () https://vuldb.com/?ctiid.327920 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.327920 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.671910 - Third Party Advisory, VDB Entry | |
| References | () https://www.campcodes.com/ - Product | 
14 Oct 2025, 14:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://github.com/feiyang85/cve/issues/1 - | 
11 Oct 2025, 12:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-10-11 12:15
Updated : 2025-10-20 18:19
NVD link : CVE-2025-11599
Mitre link : CVE-2025-11599
CVE.ORG link : CVE-2025-11599
JSON object : View
Products Affected
                campcodes
- online_apartment_visitor_management_system
