Code-Projects Online Voting System是Code-Projects组织的一个在线投票系统。 Code-Projects Online Voting System 1.0版本及之前的0.x版本存在安全漏洞,该漏洞源于Login组件中文件/authentication.php的函数test_input,对参数adminUserName/adminPassword的操作导致SQL注入,攻击者可能远程利用此漏洞。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| code-projects | Online Voting System | 0.* |
affected |
1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| code-projects | Online Voting System | 0.* |
cpe:2.3:a:code-projects:online_voting_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-14660 | 7.3 HIGH | code-projects Online Job Portal login.php sql injection |
| CVE-2026-14649 | 7.3 HIGH | code-projects Online Voting System saveVote.php test_input sql injection |
| CVE-2026-14658 | 6.3 MEDIUM | code-projects Assessment Management marking-scheme.php sql injection |
| CVE-2026-14657 | 6.3 MEDIUM | code-projects Assessment Management Database Query marking-scheme.php sql injection |
| CVE-2026-14656 | 4.3 MEDIUM | code-projects Assessment Management remove-user.php cross site scripting |
| CVE-2026-14655 | 2.4 LOW | code-projects Assessment Management view-users.php cross site scripting |
No comments yet