CVE-2026-86161: SourceCodester Online Voting System ajax.php delete_category sql injection
Published Sep 6, 2026
·Updated
A vulnerability was found in SourceCodester Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=deletecategory. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
Affected Software
1 affected component
SourceCodester Online Voting System=1.0
Event History
Sep 6, 2026
CVE Published
via MITRE·02:30 AM
Data Sourced
via MITRE·02:30 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Remote attackers can exploit the issue over the network. The provided severity vector indicates no privileges or user interaction are required.
2
What must an attacker target to trigger the vulnerability?
The attacker manipulates the ID argument sent to /ajax.php?action=delete_category. The affected component is SourceCodester Online Voting System version 1.0.
3
Is exploit code available?
Yes. The available data states that a public exploit has been disclosed and could be used.