← Terug naar overzicht

A SQL injection vulnerability was identified in SourceCodester Online Voting System version 1.0. The flaw exists in the /ajax.php?action=login file, where manipulation of the Username argument allows an attacker to perform SQL injection. The attack can be executed remotely without requiring physical access. The exploit has been publicly disclosed, increasing the risk of active exploitation. This vulnerability affects the login functionality of the web-based voting application. Successful exploitation could allow attackers to bypass authentication or extract sensitive database information. The vulnerability was reported and tracked under CVE-2026-86162.

Affected products

  • SourceCodester Online Voting System 1.0

Related CVE's

  • CVE-2026-86162

Categories

  • Database & Storage
  • Identity & Access
  • Web Technologies