vendor:
Simple Grocery Store Sales And Inventory System
by:
Saurav Shukla & Jyotsna Adhana
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: Simple Grocery Store Sales And Inventory System
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:sourcecodester:simple_grocery_store_sales_and_inventory_system:1.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Pro 10.0.18363 N/A Build 18363 + XAMPP V3.2.4
2020
Simple Grocery Store Sales And Inventory System 1.0 – Authentication Bypass
A vulnerability exists in Simple Grocery Store Sales And Inventory System 1.0 which allows an attacker to bypass authentication by using payload jyot' or 1=1# in user and password field. This can be exploited by sending a malicious request with the payload to the ajax.php file.
Mitigation:
Ensure that authentication is properly implemented and that user input is properly sanitized and validated.