← Back to overview

A SQL injection vulnerability has been identified in SourceCodester Online Voting System version 1.0. The flaw exists in the /ajax.php?action=save_user file, where manipulation of the 'ID' argument allows for SQL injection attacks. The vulnerability can be exploited remotely without requiring physical access to the system. A public exploit has already been published and is available for use by threat actors. The issue affects an unknown function within the identified file. This type of vulnerability can allow attackers to read, modify, or delete database contents, potentially compromising the integrity of voting data. The vulnerability has been catalogued in VulDB and NVD databases. Given the sensitive nature of online voting systems, exploitation could have significant implications for election integrity.

Affected products

  • SourceCodester Online Voting System 1.0

Related CVE's

  • CVE-2026-86159

Categories

  • Database & Storage
  • Web Technologies