vendor:
Helmet Store Showroom
by:
Ameer Hamza
8.8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Helmet Store Showroom
Affected Version From: v1.0
Affected Version To: v1.0
Patch Exists: NO
Related CWE:
CPE: a:oretnom23:helmet_store_showroom:1.0
Platforms Tested: Kali Linux, Apache, Mysql
2022
Helmet Store Showroom v1.0 – SQL Injection
Helmet Store Showroom v1.0 suffers from SQL injection on the login page which leads to authentication bypass of the admin account. The username parameter is vulnerable to SQLi in login page.
Mitigation:
Input validation and sanitization should be implemented to prevent SQL injection attacks.