vendor:
Online Enrollment Management System
by:
Amine Ismail
9.8
CVSS
CRITICAL
Authentication Bypass
89
CWE
Product Name: Online Enrollment Management System
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE: a:sourcecodester:online_enrollment_management_system:1.0
Platforms Tested: Windows 10, Kali Linux
2021
Online Enrollment Management System 1.0 – Authentication Bypass
Admin panel authentication can be bypassed due to a SQL injection in the login form. A curl request can be used to exploit the vulnerability, with the user_email parameter set to 'admin' OR 1=1 LIMIT 1;--+- and the user_pass parameter set to 'junk'.
Mitigation:
Input validation should be used to prevent SQL injection attacks.