CVE-2025-14889: Campcodes Advanced Voting Management System Password voters_edit.php improper authorization
A security flaw has been discovered in Campcodes Advanced Voting Management System 1.0. The impacted element is an unknown function of the file /admin/votersedit.php of the component Password Handler. Performing a manipulation of the argument ID results in improper authorization. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14889?
CVE-2025-14889 has been classified as a potentially high-severity vulnerability due to improper authorization in the Password Handler component.
How do I fix CVE-2025-14889?
To mitigate CVE-2025-14889, ensure that access control measures are correctly implemented to validate user permissions in the /admin/voters_edit.php file.
What impact does CVE-2025-14889 have on users?
CVE-2025-14889 may allow unauthorized users to manipulate voter information, which compromises the integrity of the voting management system.
Which versions of Campcodes Advanced Voting Management System are affected by CVE-2025-14889?
CVE-2025-14889 affects Campcodes Advanced Voting Management System 1.0, specifically related to the Password Handler component.
Is there a patch available for CVE-2025-14889?
As of now, there may not be a specific patch available, so users should apply necessary changes to access controls until an official update is released.