vendor:
Point of Sale System (POS)
by:
Saeed Bala Ahmed (r0b0tG4nG)
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: Point of Sale System (POS)
Affected Version From: Version 1
Affected Version To: Version 1
Patch Exists: NO
Related CWE: N/A
CPE: a:sourcecodester:point_of_sale_system_pos
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Parrot OS
2020
Point of Sale System 1.0 – Authentication Bypass
Easy authentication bypass vulnerability on the application allows an attacker to log in as Administrator. Step 1: On the login page, simply use { ' or 0=0 # } as username. Step 2: On the login page, use same query{ ' or 0=0 # } as password. All set you should be logged in as Administrator.
Mitigation:
Ensure that authentication is properly implemented and enforced.