CVE-2020-24208
CRITICALSourceCodester Online Shopping Alphaware 1.0 - SQL Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-24208. PoCs published by Ahmed Abbas.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in Online Shopping Alphaware 1.0 via SQL injection. The malicious POST request manipulates the login form to bypass authentication by injecting a tautology ('or 1=1) into the email and password fields.
Description
A SQL injection vulnerability in SourceCodester Online Shopping Alphaware 1.0 allows remote unauthenticated attackers to bypass the authentication process via email and password parameters.
Exploits (1)
This exploit demonstrates an authentication bypass vulnerability in Online Shopping Alphaware 1.0 via SQL injection. The malicious POST request manipulates the login form to bypass authentication by injecting a tautology ('or 1=1) into the email and password fields.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H