CVE-2024-35469 | SQL injection# CVE-2024-35469
#### Submitter: Kha Do
## Human Resource Management System 1.0
## Vulnerability
SQL injection
## Description
SQL injection vulnerability in /hrm/user/ in SourceCodester Human Resource Management System 1.0 allow attackers to execute arbitrary SQL commands via the password parameters.
## Affected component
/hrm/user/
## Impact
The attacker can use payload `'or'1'='1` login with administrator account without credentials.
## POC
Login with anonymous

Source code contain vulnerability

### Video
https://github.com/dovankha/SQLi_Login_User/assets/63991630/63129397-26e9-47fa-a2bc-0748fcc03c6b
[4.0K] /data/pocs/eceb9c95fd04072a0541c268d242bd555a306f4d
└── [ 855] README.md
0 directories, 1 file