Executive brief
Gate Pass Management System, a software used for managing visitor and vehicle entry/exit, contains a security flaw in its login process. An attacker can use specially crafted text in the username or password fields to trick the system into granting access without a valid password. This could allow unauthorized individuals to view sensitive visitor logs or manipulate entry records, potentially compromising physical security tracking.
Technical details
An SQL injection vulnerability exists in Gate Pass Management System 2.1 within the login-exec.php component. The application fails to properly sanitize the 'login' and 'password' POST parameters before using them in a database query. An unauthenticated remote attacker can exploit this by submitting crafted SQL payloads (e.g., ' OR 1=1 --) to bypass the authentication logic. Successful exploitation allows the attacker to gain full administrative access to the application's web interface and underlying data. A proof-of-concept exploit is publicly available.
Affected products
- Gate Pass Management System Project Gate Pass Management System 2.1
Timeline
- 2018-11-01: disclosed: Initial discovery and exploit publication by Ihsan Sencan
- 2026-05-30: advisory: CVE published and NVD record created