CVE-2023-2054: Campcodes Advanced Online Voting System positions_delete.php sql injection
A vulnerability, which was classified as critical, was found in Campcodes Advanced Online Voting System 1.0. This affects an unknown part of the file /admin/positionsdelete.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-225939.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2054?
CVE-2023-2054 is classified as a critical vulnerability.
How does CVE-2023-2054 affect the Advanced Online Voting System?
CVE-2023-2054 affects the file /admin/positions_delete.php and can lead to SQL injection through manipulation of the argument id.
How do I fix CVE-2023-2054?
To fix CVE-2023-2054, ensure input validation and use prepared statements to mitigate SQL injection risks.
Can CVE-2023-2054 be exploited remotely?
Yes, CVE-2023-2054 can be exploited remotely.
In which version of the software is CVE-2023-2054 found?
CVE-2023-2054 is found in version 1.0 of the Campcodes Advanced Online Voting System.