vendor:
Lot Reservation Management System
by:
Ankita Pal
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: Lot Reservation Management System
Affected Version From: V1.0
Affected Version To: V1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:sourcecodester:lot_reservation_management_system
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 + xampp v3.2.4
2020
lot reservation management system 1.0 – Authentication Bypass
An authentication bypass vulnerability exists in lot reservation management system 1.0. By using the payload ' or 1=1 limit 1 -- -+ for both username and password, an attacker can bypass authentication and gain access to the application as an admin.
Mitigation:
Ensure that authentication is properly implemented and that user input is properly sanitized.