Prison Management System Using PHP
cpe:2.3:a:prison_management_system_project:prison_management_system:*:*:*:*:*:*:*
A SQL injection vulnerability has been identified in Prison Management System Using PHP version 1.0. The issue arises on the Admin login page, where user input for the username field is not properly sanitized, allowing attackers to manipulate SQL queries and potentially bypass authentication.
Exploitation of this vulnerability allows for SQL injection, which could be used to manipulate the database, extract sensitive information, or bypass authentication. In this case, the vulnerability was exploited to gain unauthorized access to the admin dashboard.
To reproduce this vulnerability, log into the application using the default admin credentials. Once logged in, navigate to the Admin login page. In the username field, enter a crafted SQL injection payload that exploits the application's SQL query handling. Use a password that meets the application's requirements. After submitting the login form, the injection will be processed, and access will be granted to the admin dashboard.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.