CVE-2025-10617: SourceCodester Online Polling System positions.php sql injection
A weakness has been identified in SourceCodester Online Polling System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/positions.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10617?
CVE-2025-10617 has a high severity level due to the potential for remote SQL injection attacks.
How do I fix CVE-2025-10617?
To fix CVE-2025-10617, validate and sanitize user inputs in the /admin/positions.php file to prevent SQL injection.
What systems are affected by CVE-2025-10617?
CVE-2025-10617 affects SourceCodester Online Polling System version 1.0.
Can CVE-2025-10617 be exploited remotely?
Yes, CVE-2025-10617 can be exploited remotely, allowing attackers to execute SQL injection attacks.
What type of attack is associated with CVE-2025-10617?
CVE-2025-10617 is associated with SQL injection attacks targeting the /admin/positions.php functionality.