CVE-2018-25424

HIGH

Gate Pass Management System 2.1 SQL Injection via login-exec.php

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-25424. PoCs published by Ihsan Sencan.

AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Gate Pass Management System 2.1 via the login-exec.php endpoint. The payload uses URL-encoded SQL syntax to bypass authentication by injecting a tautology (OR 1=1) into the login and password parameters.

Description

Gate Pass Management System 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through the login and password parameters. Attackers can submit crafted POST requests to login-exec.php with SQL injection payloads in form parameters to authenticate without valid credentials and gain access to the application.

Exploits (1)

exploitdb WORKING POC
by Ihsan Sencan · textwebappsphp
https://www.exploit-db.com/exploits/45766

This exploit demonstrates a SQL injection vulnerability in Gate Pass Management System 2.1 via the login-exec.php endpoint. The payload uses URL-encoded SQL syntax to bypass authentication by injecting a tautology (OR 1=1) into the login and password parameters.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Gate Pass Management System 2.1
No auth needed
Prerequisites: access to the login-exec.php endpoint
devstral-2 · analyzed May 30, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit exploit
ExploitDB-45766
https://www.exploit-db.com/exploits/45766
Product product
Official Product Homepage
http://www.livebms.com
Third Party Advisory third-party-advisory
VulnCheck Advisory: Gate Pass Management System 2.1 SQL Injection via login-exec.php
https://www.vulncheck.com/advisories/gate-pass-management-system-sql-injection-via-login-exec-php

Scores

CVSS v3 8.2
EPSS 0.0032
EPSS Percentile 23.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
Livebms/Gate Pass Management System 2.1
Published May 30, 2026
Tracked Since May 30, 2026