CVE-2025-11667: code-projects Automated Voting System add_candidate_modal.php. sql injection
A vulnerability was found in code-projects Automated Voting System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/addcandidatemodal.php.. The manipulation of the argument firstname results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11667?
The severity of CVE-2025-11667 is high due to the potential for remote SQL injection attacks.
How do I fix CVE-2025-11667?
To fix CVE-2025-11667, sanitize and parameterize all inputs in the /admin/add_candidate_modal.php file.
Which software is affected by CVE-2025-11667?
CVE-2025-11667 affects the code-projects Automated Voting System version 1.0.
What type of vulnerability is CVE-2025-11667?
CVE-2025-11667 is an SQL injection vulnerability.
What is the attack vector for CVE-2025-11667?
The attack vector for CVE-2025-11667 allows remote execution via manipulated input in the firstname argument.