CVE-2025-13557: Campcodes Online Polling System registeracc.php sql injection
A vulnerability has been found in Campcodes Online Polling System 1.0. Affected by this issue is some unknown functionality of the file /registeracc.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13557?
CVE-2025-13557 is classified as a high-severity vulnerability due to its potential for remote SQL injection attacks.
How do I fix CVE-2025-13557?
To fix CVE-2025-13557, ensure that proper input validation and parameterized queries are implemented in the /registeracc.php file.
What systems are affected by CVE-2025-13557?
CVE-2025-13557 affects Campcodes Online Polling System version 1.0.
What kind of attack does CVE-2025-13557 allow?
CVE-2025-13557 allows attackers to execute SQL injection attacks remotely by manipulating the email parameter in the /registeracc.php file.
Is there a public disclosure of CVE-2025-13557?
Yes, CVE-2025-13557 has been publicly disclosed and is known to be exploitable.