Needyamin Library Card System SQL Injection Vulnerability in Admin Panel

Vulnerability

A critical SQL injection vulnerability has been identified in the Needyamin Library Card System version 1.0. The issue arises in the Admin Panel, specifically within the 'admindashboard.php' file. The vulnerability allows remote attackers to manipulate the 'email' and 'password' arguments, leading to unauthorized database access. This flaw could be exploited to bypass authentication and gain access to the admin dashboard.

Impact

Exploitation of this vulnerability could result in unauthorized access to the admin panel, allowing attackers to manipulate data or perform administrative functions. Additionally, this vulnerability could be combined with other attacks to enhance their effectiveness.

Reproduction

To reproduce this vulnerability, access the admin login page and inject SQL payloads into the email or password fields to bypass authentication. Once logged in, navigate to the admin dashboard.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
6.6
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.