Skip to content

dovankha/CVE-2024-35469

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

3 Commits
 
 

Repository files navigation

CVE-2024-35469

Submitter: Kha Do

Human Resource Management System 1.0

Vulnerability

SQL injection

Description

SQL injection vulnerability in /hrm/user/ in SourceCodester Human Resource Management System 1.0 allow attackers to execute arbitrary SQL commands via the password parameters.

Affected component

/hrm/user/

Impact

The attacker can use payload 'or'1'='1 login with administrator account without credentials.

POC

Login with anonymous SQL_bypass_login

Source code contain vulnerability Source_code_SQLi

Video

PoC_Video.mp4

About

CVE-2024-35469 | SQL injection

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published