Description
E Learning Script 1.0 contains an authentication bypass vulnerability that allows attackers to access the dashboard without valid credentials by manipulating login parameters. Attackers can exploit the /login.php file by sending a specific payload '=''or' to bypass authentication and gain unauthorized access to the system.
Problem types
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Credits
riamloo
References
www.exploit-db.com/exploits/47811 (ExploitDB-47811)
github.com/amitkolloldey/elearning-script (Vendor GitHub Repository)
www.vulncheck.com/.../elearning-script-authentication-bypass (VulnCheck Advisory: elearning-script 1.0 - Authentication Bypass)