BloodX
cpe:2.3:a:bloodx_project:bloodx:*:*:*:*:*:*:*
- <= 1.0
An authentication bypass vulnerability has been identified in BloodX version 1.0, specifically within the login.php file. This vulnerability allows attackers to access the dashboard without valid credentials. Exploitation involves sending a crafted payload with '=''or' parameters to bypass authentication and gain unauthorized access.
Exploitation of this vulnerability allows for unauthorized access to the dashboard, bypassing the login authentication process.
To reproduce this vulnerability, send a POST request to the login.php endpoint with the email and password fields crafted to include the payload '=''or'. This will bypass the authentication check and grant access to the dashboard.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.