Vulnerability Description
A security flaw has been discovered in Campcodes Advanced Voting Management System 1.0. The impacted element is an unknown function of the file /admin/voters_edit.php of the component Password Handler. Performing a manipulation of the argument ID results in improper authorization. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Campcodes | Advanced Voting Management System | 1.0 |
Related Weaknesses (CWE)
References
- https://gist.github.com/nikstudy576-maker/82e1e1ede9b848880aa09b87b92bc22cExploitThird Party Advisory
- https://vuldb.com/?ctiid.337378Permissions RequiredVDB Entry
- https://vuldb.com/?id.337378Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.715643Third Party AdvisoryVDB Entry
- https://www.campcodes.com/Product
FAQ
What is CVE-2025-14889?
CVE-2025-14889 is a vulnerability with a CVSS score of 5.4 (MEDIUM). A security flaw has been discovered in Campcodes Advanced Voting Management System 1.0. The impacted element is an unknown function of the file /admin/voters_edit.php of the component Password Handler...
How severe is CVE-2025-14889?
CVE-2025-14889 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-14889?
Check the references section above for vendor advisories and patch information. Affected products include: Campcodes Advanced Voting Management System.