vendor:
Student Profile Management System
by:
Borna nematzadeh (L0RD)
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: Student Profile Management System
Affected Version From: 2.0.6
Affected Version To: 2.0.6
Patch Exists: NO
Related CWE: N/A
CPE: a:phpscriptsmall:student_profile_management_system:2.0.6
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
Student Profile Management System Script 2.0.6 – Admin Panel Authentication Bypass
With this exploit, an attacker can bypass the admin panel authentication by entering any username and the password 'admin' or 'a'='a' in the admin panel login page at /admin_login.php.
Mitigation:
Ensure that authentication credentials are properly validated and that access to the admin panel is restricted to authorized personnel only.