PT-2020-16919 · Sourcecodester · Sourcecodester Library Management System

Published

2020-12-23

·

Updated

2020-12-23

·

CVE-2020-28073

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Library Management System version 1.0
Description The issue allows an attacker to bypass user authentication and impersonate any user on the system through SQL Injection.
Recommendations For SourceCodester Library Management System version 1.0, consider implementing proper input validation and sanitization to prevent SQL Injection attacks. As a temporary workaround, restrict access to sensitive user authentication modules until a patch is available.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-28073

Affected Products

Sourcecodester Library Management System