← Terug naar overzicht

A SQL injection vulnerability has been identified in SourceCodester Online Voting System version 1.0. The vulnerability exists in the /ajax.php?action=delete_category file, where manipulation of the 'ID' argument leads to SQL injection. The vulnerability can be exploited remotely without requiring local access. A public exploit has been released, increasing the risk of active exploitation. The affected product is a web-based online voting system developed by SourceCodester. The vulnerability has been assigned CVE-2026-86161 and is documented in both the NVD and VulDB databases. Given the public availability of the exploit and the sensitive nature of voting systems, this vulnerability poses a significant risk.

Affected products

  • SourceCodester Online Voting System 1.0

Related CVE's

  • CVE-2026-86161

Categories

  • Database & Storage
  • Web Technologies