在 SourceCodester Online Voting System 1.0 中发现了一个漏洞。受影响的组件是 /ajax.php?action=delete_voting 文件中的一个未知功能。通过操纵 ID 参数可导致 SQL 注入攻击。该攻击可以远程发起。该漏洞的利用方式已经公开,可能会被实际利用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | Online Voting System | 1.0 |
cpe:2.3:a:sourcecodester:online_voting_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86162 | 7.3 HIGH | SourceCodester Online Voting System ajax.php login sql injection |
| CVE-2026-86161 | 7.3 HIGH | SourceCodester Online Voting System ajax.php delete_category sql injection |
| CVE-2026-86159 | 7.3 HIGH | SourceCodester Online Voting System ajax.php save_user sql injection |
No comments yet