A vulnerability was detected in Campcodes Advanced Online Voting Management System 1.0. The impacted element is an unknown function of the file /index.php. Performing manipulation of the argument voter results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 10 Oct 2025 01:30:00 +0900

Type Values Removed Values Added
CPEs cpe:2.3:a:campcodes:advanced_online_voting_system:1.0:*:*:*:*:*:*:*

Thu, 09 Oct 2025 04:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Oct 2025 22:45:00 +0900

Type Values Removed Values Added
First Time appeared Campcodes
Campcodes advanced Online Voting System
Vendors & Products Campcodes
Campcodes advanced Online Voting System

Wed, 08 Oct 2025 06:15:00 +0900

Type Values Removed Values Added
Description A vulnerability was detected in Campcodes Advanced Online Voting Management System 1.0. The impacted element is an unknown function of the file /index.php. Performing manipulation of the argument voter results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.
Title Campcodes Advanced Online Voting Management System index.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-10-08T18:24:15.464Z

Reserved: 2025-10-07T07:27:34.386Z

Link: CVE-2025-11409

cve-icon Vulnrichment

Updated: 2025-10-08T18:23:38.130Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-07T21:15:37.697

Modified: 2025-10-09T16:23:28.043

Link: CVE-2025-11409

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-08T22:35:23Z

Weaknesses