eLection 2.0 contains an authenticated SQL injection vulnerability in the candidate management endpoint that allows attackers to manipulate database queries through the 'id' parameter. Attackers can leverage SQLMap to exploit the vulnerability, potentially gaining remote code execution by uploading backdoor files to the web application directory.
Metrics
Affected Vendors & Products
References
History
Fri, 06 Feb 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | eLection 2.0 contains an authenticated SQL injection vulnerability in the candidate management endpoint that allows attackers to manipulate database queries through the 'id' parameter. Attackers can leverage SQLMap to exploit the vulnerability, potentially gaining remote code execution by uploading backdoor files to the web application directory. | |
| Title | eLection 2.0 - 'id' SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-06T23:14:08.762Z
Reserved: 2026-02-03T16:27:45.309Z
Link: CVE-2020-37154
No data.
Status : Received
Published: 2026-02-07T00:15:55.440
Modified: 2026-02-07T00:15:55.440
Link: CVE-2020-37154
No data.
OpenCVE Enrichment
No data.