SQL Injection Vulnerability in Campcodes Online Polling System
CVE-2025-13557
Key Information:
- Vendor
Campcodes
- Status
- Vendor
- CVE Published:
- 23 November 2025
Badges
What is CVE-2025-13557?
A security flaw has been identified in Campcodes Online Polling System version 1.0, specifically within the /registeracc.php file. The vulnerability arises from insufficient input validation on the email parameter, allowing attackers to execute arbitrary SQL code. This SQL injection vulnerability can be exploited by an attacker remotely, potentially compromising sensitive user data and the integrity of the database. Given the public disclosure of this exploit, immediate attention to patching and securing affected systems is crucial.
Affected Version(s)
Online Polling System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
