---
id: CVE-2025-11599
title: >-
  A weakness has been identified in Campcodes Online Apartment Visitor
  Management System 1.0
summary: >-
  A weakness has been identified in Campcodes Online Apartment Visitor
  Management System 1.0. This impacts an unknown function of the file
  /forgot-password.php. This manipulation of the argument email causes sql
  injection. It is possible t…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-89
  - CWE-89
vendor: campcodes
product: online_apartment_visitor_management_system
affected:
  - online_apartment_visitor_management_system = 1.0
published: '2025-10-11'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T13:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11599'
references:
  - url: 'https://github.com/feiyang85/cve/issues/1'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.327920'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.327920'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.671910'
    label: cna@vuldb.com
  - url: 'https://www.campcodes.com/'
    label: cna@vuldb.com
  - url: 'https://github.com/feiyang85/cve/issues/1'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00421
epssPercentile: 0.34352
ingestedAt: '2026-10-08T13:42:55.110Z'
---

## Overview

A weakness has been identified in Campcodes Online Apartment Visitor Management System 1.0. This impacts an unknown function of the file /forgot-password.php. This manipulation of the argument email causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.

## Affected

- `online_apartment_visitor_management_system = 1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
