Elaniin CMS Authentication Bypass Vulnerability
Vulnerability
An authentication bypass vulnerability has been identified in Elaniin CMS version 1.0. This vulnerability allows attackers to gain unauthorized access to the dashboard by exploiting SQL injection on the login page. By sending crafted email and password parameters containing specific payloads, attackers can manipulate the authentication process and access the system.
Impact
Exploitation of this vulnerability allows for unauthorized access to the application's dashboard, bypassing normal authentication mechanisms.
Reproduction
To reproduce this vulnerability, send a POST request to 'login.php' with the email and password fields crafted to include the payload '='''or''. This SQL injection payload tricks the application into bypassing authentication checks.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
