Description
Part-DB 0.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to login by injecting SQL syntax into authentication parameters. Attackers can submit a single quote followed by 'or' in the login form to bypass credential validation and gain unauthorized access to the application.
Problem types
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Credits
Marvoloo
References
www.exploit-db.com/exploits/47547 (ExploitDB-47547)
github.com/Part-DB/Part-DB/ (Part-DB Legacy GitHub Repository)
www.vulncheck.com/...t-db-authentication-bypass-via-loginphp (VulnCheck Advisory: Part-DB 0.4 Authentication Bypass via login.php)