PT-2025-30945 · Code Projects · Voting System 1.0

Ic0Rner

·

Published

2025-07-26

·

Updated

2025-08-05

·

CVE-2025-8174

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions code-projects Voting System version 1.0
Description A critical vulnerability exists in code-projects Voting System 1.0, related to unrestricted file upload. The issue affects an unknown functionality within the /admin/candidates add.php file. Manipulation of the photo argument allows for unrestricted uploads, and the attack can be launched remotely. The exploit has been publicly disclosed.
Recommendations Restrict access to the /admin/candidates add.php file. As a temporary workaround, consider disabling the file upload functionality within the /admin/candidates add.php file until a patch is available.

Exploit

Fix

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-8174

Affected Products

Voting System 1.0