SQL Injection Vulnerability in Poll Maker by Ays-Pro
CVE-2025-26971
7.6HIGH
Key Information:
- Vendor
- Ays-pro
- Status
- Poll Maker
- Vendor
- CVE Published:
- 25 February 2025
Summary
A vulnerability in Poll Maker developed by Ays-Pro allows for blind SQL injection due to improper neutralization of special elements within SQL commands. This issue affects various versions of Poll Maker, specifically from n/a up to 5.6.5, which could potentially allow attackers to manipulate database queries, extract sensitive information, or compromise the integrity of the application's data.
Affected Version(s)
Poll Maker <= 5.6.5
References
CVSS V3.1
Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Webula (Patchstack Alliance)