CVE-2025-14889 is an improper authorization vulnerability affecting Campcodes Advanced Voting Management System 1.0, specifically within the password handler component of the /admin/voters_edit.php file. By manipulating the ID argument, an authenticated attacker can achieve remote unauthorized access, leading to potential low impact on confidentiality, integrity, and availability. Rated as Medium severity with a CVSS score of 6.3, this flaw has publicly available exploit code, though it is not currently listed on the CISA KEV catalog or experiencing active exploitation. Community discussion and media coverage remain minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:campcodes:advanced_voting_management_system:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.