CVE-2023-2055
Plain English Summary
AI-powered analysis for quick understanding
This vulnerability allows an attacker to inject malicious scripts into the voting system, potentially stealing sensitive information from users who visit the affected page. It can be exploited remotely, meaning an attacker doesn't need physical access to the system, making it a significant risk for any online voting setup.
Technical Description
A vulnerability has been found in Campcodes Advanced Online Voting System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/config_save.php. The manipulation of the argument title leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-225940.
CVSS Vector Analysis
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Quick Information
Published
Apr 14, 2023
almost 3 years ago
Last Modified
Mar 18, 2026
20 days ago
Vendor
campcodes
Product
advanced online voting system
Related Vulnerabilities
An attacker can inject malicious scripts into the Campcodes Online Traffic Offense Management System, allowing them to execute harmful actions in the context of a user's session. This can happen remotely when the attacker manipulates a specific part of the URL, making it important for users to be cautious when accessing links related to this system.
This vulnerability allows an attacker to inject malicious scripts into the online traffic offense management system, potentially compromising user data or hijacking user sessions. The attack can be carried out remotely, meaning the attacker doesn't need physical access to the system, making it a significant risk for users.
This vulnerability allows an attacker to remotely manipulate the system and access or modify the database by exploiting a flaw in the way the application handles certain input. It specifically affects the online traffic offense management system and requires no special access, making it a high-risk issue for users of the software.
This vulnerability allows an attacker to remotely manipulate the system's database by exploiting a flaw in the Online Traffic Offense Management System, potentially leading to unauthorized access to sensitive data. The attacker needs to send a specially crafted request to the system, making it critical for users to patch the software immediately to prevent exploitation.
This vulnerability allows an attacker to remotely execute SQL injection attacks on the Campcodes Online Traffic Offense Management System, potentially giving them access to sensitive data stored in the database. It can be exploited by manipulating the password input in the login process, making it critical for users to secure their systems immediately.