CVE-2019-25494
HIGHDoditsolutions Homey BNB (Airbnb Clone Script) >=V4 - SQL Injection & Auth Bypass via Admin Panel
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25494. PoCs published by Ahmet Ümit BAYRAM.
AI-analyzed exploit summary The exploit demonstrates multiple SQL injection vulnerabilities in Homey BNB (Airbnb Clone Script) V4, targeting various GET parameters with time-based and boolean-based payloads. It includes PoCs for authentication bypass and SQLi in admin and user-facing endpoints.
Description
Homey BNB V4 contains an SQL injection vulnerability in the administration panel login that allows unauthenticated attackers to bypass authentication by injecting SQL syntax into username and password fields. Attackers can submit SQL operators like '=' 'or' in both credentials to manipulate the authentication query and gain unauthorized access to the admin panel.
Exploits (1)
The exploit demonstrates multiple SQL injection vulnerabilities in Homey BNB (Airbnb Clone Script) V4, targeting various GET parameters with time-based and boolean-based payloads. It includes PoCs for authentication bypass and SQLi in admin and user-facing endpoints.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N