vendor:
Company Visitor Management System (CVMS)
by:
Oğuz Türkgenç
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: Company Visitor Management System (CVMS)
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:phpgurukul:company_visitor_management_system_using_php_and_mysql
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 Enterprise SP1 + XAMPP V3.2.3
2020
Company Visitor Management System (CVMS) 1.0 – Authentication Bypass
An authentication bypass vulnerability exists in Company Visitor Management System (CVMS) 1.0. An attacker can use payload ot' or 1=1# in user and password field to bypass authentication and gain access to the application as admin.
Mitigation:
Ensure that authentication is properly implemented and enforced.