A flaw has been found in Campcodes Online Polling System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/checklogin.php. Executing manipulation of the argument myusername can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 25 Nov 2025 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Campcodes
Campcodes online Polling System
Vendors & Products Campcodes
Campcodes online Polling System

Mon, 24 Nov 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 23 Nov 2025 17:15:00 +0000

Type Values Removed Values Added
Title Campcodes Online Polling System checklogin.php Nusẽtɔwo aɖe le be wotsɔe ɖe agbe. sql injection Campcodes Online Polling System checklogin.php sql injection

Sun, 23 Nov 2025 16:15:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Campcodes Online Polling System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/checklogin.php. Executing manipulation of the argument myusername can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used.
Title Campcodes Online Polling System checklogin.php Nusẽtɔwo aɖe le be wotsɔe ɖe agbe. sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-11-24T16:20:46.173Z

Reserved: 2025-11-22T15:39:04.970Z

Link: CVE-2025-13556

cve-icon Vulnrichment

Updated: 2025-11-24T16:20:34.383Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-23T16:15:46.407

Modified: 2025-11-25T22:16:42.557

Link: CVE-2025-13556

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-25T11:02:40Z