SQL Injection Vulnerability in Voting System by Code-Projects
CVE-2025-7557
Key Information:
- Vendor
Code-projects
- Status
- Vendor
- CVE Published:
- 14 July 2025
Badges
What is CVE-2025-7557?
A SQL injection vulnerability exists in the Voting System 1.0, specifically in the /admin/voters_row.php
file. This vulnerability arises from improper handling of the ID argument, allowing attackers to execute arbitrary SQL queries. The exploitation can be performed remotely, posing significant risks to data integrity and security. Given that this vulnerability has been publicly disclosed, organizations using this software should take immediate action to mitigate potential threats and secure their applications.
Affected Version(s)
Voting System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved