A SQL injection vulnerability has been identified in CodeAstro Apartment Visitor Management System version 1.0. The vulnerability exists in the password-recovery.php file, where manipulation of the email argument allows SQL injection attacks. The flaw can be exploited remotely without requiring physical access to the system. A public exploit is already available, increasing the risk of active exploitation. The vulnerability affects an unknown functionality within the password recovery flow. Attackers could potentially extract or manipulate database contents through this vector. The issue has been catalogued under CVE-2026-77020 and reported via VulDB and GitHub.