Improper Authorization in Campcodes Advanced Voting Management System
CVE-2025-14889
Key Information:
- Vendor
Campcodes
- Vendor
- CVE Published:
- 18 December 2025
Badges
What is CVE-2025-14889?
A security flaw exists in the Campcodes Advanced Voting Management System 1.0, specifically affecting the /admin/voters_edit.php file within the Password Handler component. This vulnerability allows for improper authorization when the argument ID is manipulated by an attacker. The nature of this flaw enables potential remote exploitation, increasing the risk of unauthorized access and manipulation of sensitive user data. As the exploit code has been made public, it is crucial for users of the system to apply necessary security measures to mitigate potential risks. For further details, refer to the official Campcodes website and related security advisories.
Affected Version(s)
Advanced Voting Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
