Shipping System CMS SQL Injection Vulnerability
Vulnerability
A SQL injection vulnerability has been identified in Shipping System CMS version 1.0. This vulnerability allows unauthenticated attackers to bypass authentication by injecting SQL code through the username parameter. Exploitation involves using boolean-based blind SQL injection techniques in POST requests to the admin login endpoint, enabling attackers to authenticate without valid credentials.
Impact
Exploitation of this vulnerability allows for authentication bypass, potentially leading to unauthorized access to the application.
Reproduction
To reproduce this vulnerability, send a POST request to the admin login endpoint with a crafted SQL payload in the username parameter. The payload should be designed to exploit boolean-based blind SQL injection, such as by using a condition that is always true.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
