CVE-2025-10078: SourceCodester Online Polling System candidates.php sql injection
Published Sep 8, 2025
·Updated
A vulnerability was detected in SourceCodester Online Polling System 1.0. Affected is an unknown function of the file /admin/candidates.php. Performing manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.
Affected Software
2 affected components
Sourcecodester Online Polling System
Razormist Online Polling System=1.0
Event History
Sep 8, 2025
CVE Published
via MITRE·02:02 AM
Data Sourced
via MITRE·02:02 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-10078?
CVE-2025-10078 has been classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2025-10078?
To fix CVE-2025-10078, validate and sanitize all input parameters in the /admin/candidates.php file.
3
What systems are affected by CVE-2025-10078?
CVE-2025-10078 affects SourceCodester Online Polling System version 1.0.
4
Can CVE-2025-10078 be exploited remotely?
Yes, CVE-2025-10078 is a remotely exploitable vulnerability.
5
What type of vulnerability is CVE-2025-10078?
CVE-2025-10078 is classified as a SQL injection vulnerability.