Junglewise Threat Intelligence

CVE-2026-14648: code-projects Online Voting System SQL injection in Login

CVE-2026-14648 · Severity: high · CVSS 7.3 · Published 2026-07-04

Vendors: Code-Projects.

Executive brief

A security vulnerability exists in the Online Voting System, a web application used for managing elections. An attacker can bypass the login screen to gain full administrative access without a valid password. This could allow an unauthorized person to view sensitive voter information, change election results, or modify candidate details.

Technical details

A SQL injection vulnerability exists in the admin authentication mechanism within `/authentication.php`. The application uses a `test_input()` function that calls `htmlspecialchars()` without the `ENT_QUOTES` flag, failing to escape single quotes. Consequently, the `adminUserName` and `adminPassword` POST parameters are interpolated directly into a SQL query. A remote, unauthenticated attacker can use a crafted payload (e.g., `admin'-- -`) to comment out the password check and gain full administrative access to the `cpanel.php` dashboard. As of the advisory date, the vulnerability is reported as unpatched.

Affected products

  • code-projects Online Voting System 0.x, 1.0

Timeline

  • 2026-06-02: disclosed: Public exploit/PoC disclosed on GitHub Gist
  • 2026-07-04: advisory: NVD/VulDB advisory published

References

Related threats