vendor:
Judging Management System
by:
Angelo Pio Amirante
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: Judging Management System
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE: a:sourcecodester:judging_management_system
Platforms Tested: Windows 10 on XAAMP server
2022
Judging Management System v1.0 – Authentication Bypass
An attacker can bypass the login page and access the dashboard page by using a payload of 'or 1=1-- - for the username and random words for the password.
Mitigation:
Implement proper authentication and authorization mechanisms.