vendor:
Simple Subscription Website
by:
Daniel Haro (Dirox)
9.8
CVSS
CRITICAL
SQL Injection
89
CWE
Product Name: Simple Subscription Website
Affected Version From: Simple Subscription Website 1.0
Affected Version To: Simple Subscription Website 1.0
Patch Exists: YES
Related CWE: CVE-2021-43140
CPE: a:sourcecodester:simple_subscription_website:1.0
Platforms Tested: Windows, xampp
2021
Simple Subscription Website 1.0 – SQLi Authentication Bypass
SQL Injection vulnerability exists in Sourcecodester. Simple Subscription Website 1.0. An account takeover exists with the payload: admin' or 1=1-- -
Mitigation:
Input validation and sanitization should be implemented to prevent SQL injection attacks.