Shipping System CMS SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability has been identified in Shipping System CMS version 1.0. This vulnerability allows unauthenticated attackers to bypass authentication by injecting SQL code through the username parameter. Exploitation involves using boolean-based blind SQL injection techniques in POST requests to the admin login endpoint, enabling attackers to authenticate without valid credentials.

Impact

Exploitation of this vulnerability allows for authentication bypass, potentially leading to unauthorized access to the application.

Reproduction

To reproduce this vulnerability, send a POST request to the admin login endpoint with a crafted SQL payload in the username parameter. The payload should be designed to exploit boolean-based blind SQL injection, such as by using a condition that is always true.

Added: Mar 26, 2026, 12:23 PM
Updated: Mar 26, 2026, 12:23 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
8.7
remediation
0.0
relevance
4.7
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.