Description
BloodX 1.0 contains an authentication bypass vulnerability in login.php that allows attackers to access the dashboard without valid credentials. Attackers can exploit the vulnerability by sending a crafted payload with '=''or' parameters to bypass login authentication and gain unauthorized access.
Problem types
Authentication Bypass Using an Alternate Path or Channel
Product status
Credits
riamloo
References
www.exploit-db.com/exploits/47842 (ExploitDB-47842)
github.com/diveshlunker/BloodX (BloodX GitHub Repository)
www.vulncheck.com/advisories/bloodx-authentication-bypass (VulnCheck Advisory: BloodX 1.0 - Authentication Bypass)