vendor:
Barangay Management System
by:
BKpatron
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: Barangay Management System
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:sourcecodester:barangay_management_system:1.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2020
Barangay Management System 1.0 – Authentication Bypass
Attacker can bypass the login page and access the dashboard page by sending a POST request with the payload '=''or' to the vulnerable file adminlogin.php.
Mitigation:
Implement proper authentication and authorization mechanisms.