PT-2020-16103 · Sourcecodester · Sourcecodester Library Management System

Ko-Kn3T

·

Published

2020-09-22

·

Updated

2021-07-21

·

CVE-2020-25514

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sourcecodester Simple Library Management System version 1.0
Description The issue is related to Incorrect Access Control, which can be exploited via the Login Panel. The vulnerable endpoint is "http:///lms/admin.php".
Recommendations For Sourcecodester Simple Library Management System version 1.0, consider restricting access to the admin.php endpoint until a proper fix is applied. As a temporary workaround, review and strengthen the access control mechanisms for the Login Panel to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-25514

Affected Products

Sourcecodester Library Management System