CVE-2020-36945

HIGH

WebDamn User Registration Login System - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-36945. PoCs published by Aakash Madaan.

AI-analyzed exploit summary This exploit describes an SQL injection authentication bypass vulnerability in WebDamn User Registration & Login System. The payload ' OR '1'='1 can be used in both username and password fields to bypass authentication if a valid email address is known.

Description

WebDamn User Registration Login System contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authentication by manipulating email credentials. Attackers can inject the payload '<email>' OR '1'='1' in both username and password fields to gain unauthorized access to the user panel.

Exploits (1)

exploitdb WRITEUP
by Aakash Madaan · textwebappsmultiple
https://www.exploit-db.com/exploits/49170

This exploit describes an SQL injection authentication bypass vulnerability in WebDamn User Registration & Login System. The payload ' OR '1'='1 can be used in both username and password fields to bypass authentication if a valid email address is known.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: WebDamn User Registration & Login System with User Panel
No auth needed
Prerequisites: Valid email address of a registered user
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4

Scores

CVSS v3 8.2
EPSS 0.0041
EPSS Percentile 32.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
WEBDAMN.COM/WebDamn User Registration & Login System with User Panel N/A (Default)
Published Jan 28, 2026
Tracked Since Feb 18, 2026