Impact
The vulnerability is an SQL injection flaw in the Ajax handler at /ajax.php?action=save_user of SourceCodester Online Voting System 1.0. An attacker can manipulate the ID parameter, which is not properly filtered, to inject arbitrary SQL statements. This weakness is categorized as CWE‑74 for improper input sanitization and CWE‑89 for SQL injection. The description indicates the attack can be initiated remotely and that an exploit has already been published.
Affected Systems
The affected product is SourceCodester Online Voting System version 1.0. No other versions or vendor products are listed as vulnerable.
Risk and Exploitability
The CVSS score of 6.9 denotes moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA KEV, but an exploit is public and can be triggered remotely. No authentication or privilege restrictions are mentioned, which suggests that any user with network access to the application might be able to exploit the flaw, increasing the likelihood of successful exploitation.
OpenCVE Enrichment