Junglewise Threat Intelligence

CVE-2026-14649: code-projects Online Voting System SQL injection in saveVote.php

CVE-2026-14649 · Severity: high · CVSS 7.3 · Published 2026-07-04

Vendors: Code-Projects.

Executive brief

A security vulnerability exists in the code-projects Online Voting System, a web application used for managing digital elections. An attacker can exploit this flaw to manipulate the voting process, including submitting fraudulent votes or altering election results. This could lead to a complete loss of integrity in the voting system and potential exposure of voter information.

Technical details

A SQL injection vulnerability exists in the 'test_input' function within /saveVote.php of code-projects Online Voting System 1.0. The root cause is the improper neutralization of special elements; specifically, the application uses htmlspecialchars() without the ENT_QUOTES flag, failing to escape single quotes before concatenating the voterName, voterEmail, voterID, and selectedCandidate POST parameters into an INSERT query. An unauthenticated remote attacker can exploit this by sending crafted HTTP POST requests to the vulnerable endpoint. This allows for time-based blind SQL injection, enabling the insertion of fraudulent records, potential data extraction from the database, or disruption of service through malformed queries. As of the advisory date, the vulnerability remains unpatched.

Affected products

  • code-projects Online Voting System 1.0

Timeline

  • 2026-06-01: disclosed: Initial discovery and PoC shared via GitHub Gist
  • 2026-07-04: advisory: CVE published and indexed by NVD/VulDB

References

Related threats