Impact
The flaw exists in the Ajax handler for the delete voting operation. A crafted request that alters the ID argument can inject arbitrary SQL. The injected code runs in the context of the database, allowing an attacker to read, modify or delete voting records, thereby compromising the confidentiality, integrity, and availability of election data.
Affected Systems
This vulnerability impacts SourceCodester Online Voting System version 1.0. No other specific affected versions are listed, and no patch has been published by the vendor according to the available information.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.9, reflecting moderate severity. The EPSS score is not available and the issue is not listed in the CISA KEV catalog. The attack is remote and can be launched via a crafted HTTP request to /ajax.php?action=delete_voting, and the vulnerability has been publicly disclosed, making exploitation a realistic threat.
OpenCVE Enrichment