Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-25347. PoCs published by Anıl Baran Yelken.
AI-analyzed exploit summary This is a SQL injection exploit targeting the 'username' parameter in thesystem App 1.0. It demonstrates an authentication bypass by injecting a tautology (' or '1=1) to retrieve user data.
Description
thesystem App 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating the username parameter. Attackers can inject malicious SQL code like ' or '1=1 to the username field to gain unauthorized access to user accounts.
Exploits (1)
This is a SQL injection exploit targeting the 'username' parameter in thesystem App 1.0. It demonstrates an authentication bypass by injecting a tautology (' or '1=1) to retrieve user data.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N