CVE-2026-86162: SourceCodester Online Voting System ajax.php login sql injection
Published Sep 6, 2026
·Updated
A vulnerability was determined in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /ajax.php?action=login. Executing a manipulation of the argument Username can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
1 affected component
SourceCodester Online Voting System=1.0
Event History
Sep 6, 2026
CVE Published
via MITRE·02:45 AM
Data Sourced
via MITRE·02:45 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attack is remote and requires no privileges or user interaction. An attacker can target the login action in /ajax.php by manipulating the Username argument.
2
Is public exploit information available?
Yes. The exploit has been publicly disclosed and may be used by attackers.
3
Which deployments are known to be affected?
The affected product identified in the available data is SourceCodester Online Voting System 1.0. The provided information does not identify configuration-specific conditions or mitigations.