CVE-2025-11417 PUBLISHED

Campcodes Advanced Online Voting Management System voters_add.php unrestricted upload

Assigner: VulDB
Reserved: 07.10.2025 Published: 07.10.2025 Updated: 07.10.2025

A weakness has been identified in Campcodes Advanced Online Voting Management System 1.0. This vulnerability affects unknown code of the file /admin/voters_add.php. Executing manipulation of the argument photo can lead to unrestricted upload. The attack can be launched remotely. The exploit has been made available to the public and could be exploited.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 5.3

Product Status

Vendor Campcodes
Product Advanced Online Voting Management System
Versions
  • Version 1.0 is affected

Credits

  • hbesljx (VulDB User) reporter

References

Problem Types

  • Unrestricted Upload CWE
  • Improper Access Controls CWE