A SQL injection vulnerability has been identified in CodeAstro Apartment Visitor Management System version 1.0. The vulnerability exists in the /apartment-visitor/forgotpw.php file, where manipulation of the 'secode' argument can lead to SQL injection. The attack can be launched remotely without requiring local access. A public exploit has already been disclosed and is available for use, increasing the risk of exploitation. The vulnerability affects an unknown function within the identified file. Given the public disclosure and remote exploitability, this poses a significant risk to systems running the affected software version. Users of CodeAstro Apartment Visitor Management System 1.0 are advised to apply patches or mitigations promptly.