CVE-2025-7149: Campcodes Advanced Online Voting System candidates_delete.php sql injection
Published Jul 7, 2025
·Updated
A vulnerability was found in Campcodes Advanced Online Voting System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/candidatesdelete.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Campcodes Advanced Online Voting System
Campcodes Advanced Online Voting System=1.0
Event History
Jul 7, 2025
CVE Published
via MITRE·10:02 PM
Data Sourced
via MITRE·10:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Jun 12, 58473
Event
via NVD·05:54 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-7149?
CVE-2025-7149 has been classified as critical.
2
What type of vulnerability is CVE-2025-7149?
CVE-2025-7149 is an SQL injection vulnerability.
3
How do I fix CVE-2025-7149?
To fix CVE-2025-7149, validate and sanitize all input parameters in the /admin/candidates_delete.php file.
4
Which software is affected by CVE-2025-7149?
CVE-2025-7149 affects Campcodes Advanced Online Voting System version 1.0.
5
What can attackers achieve with CVE-2025-7149?
Attackers can execute arbitrary SQL commands leading to potential data exposure or manipulation.