CVE-2025-9699: SourceCodester Online Polling System Code checklogin.php sql injection
A vulnerability was detected in SourceCodester Online Polling System Code 1.0. This vulnerability affects unknown code of the file /admin/checklogin.php. The manipulation of the argument myusername results in sql injection. The attack may be performed from a remote location. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9699?
CVE-2025-9699 is categorized as a high severity vulnerability due to the potential for remote SQL injection attacks.
How do I fix CVE-2025-9699?
To fix CVE-2025-9699, developers should implement input validation and use prepared statements to safeguard against SQL injection in the /admin/checklogin.php file.
What systems are affected by CVE-2025-9699?
CVE-2025-9699 affects the SourceCodester Online Polling System Code version 1.0.
Can CVE-2025-9699 be exploited remotely?
Yes, CVE-2025-9699 can be exploited remotely by manipulating the 'myusername' parameter.
What kind of attack is possible with CVE-2025-9699?
CVE-2025-9699 allows for SQL injection attacks, which can compromise database integrity and confidentiality.