vendor:
CASAP Automated Enrollment System
by:
Himanshu Shukla
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: CASAP Automated Enrollment System
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:sourcecodester:casap_automated_enrollment_system:1.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu + XAMPP 7.4.4
2021
CASAP Automated Enrollment System 1.0 – Authentication Bypass
CASAP Automated Enrollment System 1.0 is vulnerable to authentication bypass. An attacker can exploit this vulnerability by setting a cookie and sending a POST request with a username of 'or 1 or' and a blank password. If successful, the attacker will be able to access the dashboard without authentication.
Mitigation:
Ensure that authentication is properly implemented and that user input is properly sanitized.