Election Services Co. (ESC) Internet Election Service is...
Critical severity
Unreviewed
Published
Oct 10, 2023
to the GitHub Advisory Database
•
Updated Mar 21, 2024
Description
Published by the National Vulnerability Database
Oct 10, 2023
Published to the GitHub Advisory Database
Oct 10, 2023
Last updated
Mar 21, 2024
Election Services Co. (ESC) Internet Election Service is vulnerable to SQL injection in multiple pages and parameters. These vulnerabilities allow an unauthenticated, remote attacker to read or modify data for any elections that share the same backend database. ESC deactivated older and unused elections and enabled web application firewall (WAF) protection for current and future elections on or around 2023-08-12.
References