vendor:
College-Management-System
by:
Cakes
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: College-Management-System
Affected Version From: 1.2
Affected Version To: 1.2
Patch Exists: NO
Related CWE: N/A
CPE: a:ajinkyabodade:college-management-system
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: CentOS 7
2019
College-Management-System 1.2 – Authentication Bypass
Easy authentication bypass vulnerability on the application allowing the attacker to log in as the school principal. Simply replay the below Burp request or use Curl. Payload: ' or 0=0 #
Mitigation:
Ensure that authentication is properly implemented and that user input is properly sanitized.