Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-29414
HistoryApr 18, 2023 - 12:00 a.m.

Campcodes Advanced Online Voting System SQL Injection Vulnerability (CNVD-2023-29414)

2023-04-1800:00:00
China National Vulnerability Database
www.cnvd.org.cn
40
campcodes
online voting
sql injection
vulnerability
validation
sql commands
database security

EPSS

0.002

Percentile

54.8%

Campcodes Advanced Online Voting System is an online voting system. Campcodes Advanced Online Voting System v1.0 is vulnerable to SQL injection. The vulnerability stems from the lack of validation of external input SQL statements in the parameter voter of the file login.php, which can be exploited by attackers to execute illegal SQL commands to steal sensitive database data.

EPSS

0.002

Percentile

54.8%

Related for CNVD-2023-29414