← Terug naar overzicht

A SQL injection vulnerability has been identified in SourceCodester Online Voting System version 1.0. The vulnerability exists in the /ajax.php?action=delete_voting file, where manipulation of the 'ID' argument allows for SQL injection attacks. The attack can be launched remotely without requiring physical access to the target system. A public exploit has been disclosed and is available for use, increasing the risk of exploitation. The vulnerability affects an unknown function within the identified file. Attackers could potentially manipulate the database through this injection point. The issue has been assigned CVE-2026-86160 and is tracked in multiple vulnerability databases including NVD and VulDB.

Affected products

  • SourceCodester Online Voting System 1.0

Related CVE's

  • CVE-2026-86160

Categories

  • Database & Storage
  • Web Technologies