top of page
perceptive_background_267k.jpg

A SQL injection vulnerability exists in the login functionality of Fikir Odalari AdminPando 1.0.1 before 2026-01-26. The username and password parameters are vu…

Published:

2 februari 2026 om 23:00:00

Alert date:

3 februari 2026 om 21:01:17

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access, Database & Storage

A critical SQL injection vulnerability in Fikir Odalari AdminPando 1.0.1 allows unauthenticated attackers to bypass authentication through vulnerable username and password parameters in the login functionality. Successful exploitation grants complete administrative access to the application, enabling attackers to manipulate public-facing website content through HTML/DOM manipulation. The vulnerability affects versions before 2026-01-26 and represents a complete authentication bypass, making it a high-severity security issue.

Technical details

Mitigation steps:

Affected products:

Fikir Odalari AdminPando

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page