SOUND4 Impact, First, Pulse, and Eco SQL Injection Vulnerability in Authentication Mechanism
Vulnerability
A SQL injection vulnerability has been identified in SOUND4 IMPACT, FIRST, PULSE, and ECO version 2.x. The issue resides in the 'index.php' authentication process, where the 'password' POST parameter is not properly sanitized. This flaw allows attackers to inject malicious SQL code, manipulate login credentials, and bypass authentication, potentially leading to unauthorized access.
Impact
Exploitation of this vulnerability allows for authentication bypass, unauthorized system access, and manipulation of login credentials.
Reproduction
To reproduce this vulnerability, send a POST request to 'index.php' with a crafted 'password' parameter that includes SQL injection payloads. The injection can manipulate SQL queries to bypass authentication.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
