vendor:
Online Movie Streaming
by:
Richard Jones
7.5
CVSS
HIGH
Admin Authentication Bypass
287
CWE
Product Name: Online Movie Streaming
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10 Home 19041 (x64_86) + XAMPP 7.2.34
2021
Online Movie Streaming 1.0 – Admin Authentication Bypass
The exploit allows an attacker to bypass the authentication mechanism in the Online Movie Streaming 1.0 application. By manipulating the login form parameters, an attacker can gain administrative access to the application.
Mitigation:
The vendor should implement proper input validation and secure authentication mechanisms to prevent this vulnerability. Users should update to a patched version of the software.