Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-25320. PoCs published by riamloo.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in elearning-script 1.0 via SQL injection in the login.php file. The payload '=''or' manipulates the SQL query to bypass authentication and access the dashboard.
Description
E Learning Script 1.0 contains an authentication bypass vulnerability that allows attackers to access the dashboard without valid credentials by manipulating login parameters. Attackers can exploit the /login.php file by sending a specific payload '=''or' to bypass authentication and gain unauthorized access to the system.
Exploits (1)
This exploit demonstrates an authentication bypass vulnerability in elearning-script 1.0 via SQL injection in the login.php file. The payload '=''or' manipulates the SQL query to bypass authentication and access the dashboard.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N