在 SourceCodester 在线投票系统 1.0 中发现了一个漏洞。受影响的组件是文件 /ajax.php 中 action=save_user 参数对应的未知函数。通过对参数 ID 进行操控,可触发 SQL 注入。该攻击可由远程发起。此漏洞的利用方式(exploit)已经公开,可能被实际利用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | Online Voting System | 1.0 |
cpe:2.3:a:sourcecodester:online_voting_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86162 | 7.3 HIGH | SourceCodester Online Voting System ajax.php login sql injection |
| CVE-2026-86161 | 7.3 HIGH | SourceCodester Online Voting System ajax.php delete_category sql injection |
| CVE-2026-86160 | 7.3 HIGH | SourceCodester Online Voting System ajax.php delete_voting sql injection |
No comments yet