Library CMS SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability has been identified in Library CMS version 1.0. This vulnerability allows unauthenticated attackers to bypass authentication by injecting SQL code through the username parameter. Exploitation involves sending POST requests to the admin login endpoint with boolean-based blind SQL injection payloads in the username field, manipulating database queries to gain unauthorized access.

Impact

Exploitation of this vulnerability could lead to unauthorized access by bypassing authentication mechanisms.

Reproduction

To reproduce this vulnerability, send a POST request to the admin login endpoint, including a boolean-based blind SQL injection payload in the username field. The injected SQL code can be used to manipulate database queries and bypass authentication.

Added: Mar 26, 2026, 12:31 PM
Updated: Mar 26, 2026, 12:31 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
8.7
remediation
0.0
relevance
4.7
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.