vendor:
Online Thesis Archiving System 1.0
by:
Yehia Elghaly (YME)
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Online Thesis Archiving System 1.0
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE: a:sourcecodester:online_thesis_archiving_system_1.0
Platforms Tested: Windows, xampp
2020
Online Thesis Archiving System 1.0 – SQLi Authentication Bypass
SQL Injection vulnerability exists in Online Thesis Archiving System 1.0 1.0. An admin account takeover exists with the payload: admin' # - admin' or '1'='1
Mitigation:
Input validation and sanitization should be used to prevent SQL injection attacks.