vendor:
Online Polling System
by:
AppleBois
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: Online Polling System
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE: a:online_polling_system:1.0
Platforms Tested:
2020
Online Polling System 1.0 – Authentication Bypass
Unauthenticated user can perform SQL Injection to bypass the login mechanism on /admin/checklogin.php in the Online Polling System 1.0. The vulnerability is due to the lack of proper input validation on the 'myusername' and 'mypassword' parameters. An attacker can exploit this vulnerability to gain unauthorized access to the administration control panel.
Mitigation:
To mitigate this vulnerability, the software should implement proper input validation and sanitization techniques to prevent SQL injection attacks. Additionally, strong and unique passwords should be enforced for user accounts.