vendor:
Gym Management System
by:
Jyotsna Adhana
8.8
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: Gym Management System
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:sourcecodester:gym_management_system:1.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Pro 10.0.18363 N/A Build 18363 + XAMPP V3.2.4
2020
Gym Management System 1.0 – Authentication Bypass
An authentication bypass vulnerability exists in Gym Management System 1.0. By sending a specially crafted request with payload jyot' or 1=1# in Username and Password field, an attacker can bypass authentication and gain access to the admin panel.
Mitigation:
Ensure that authentication is properly implemented and enforced.