Part-DB 0.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to login by injecting SQL syntax into authentication parameters. Attackers can submit a single quote followed by 'or' in the login form to bypass credential validation and gain unauthorized access to the application.
Metrics
Affected Vendors & Products
References
History
Thu, 05 Mar 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Part-db Project
Part-db Project part-db |
|
| CPEs | cpe:2.3:a:part-db_project:part-db:0.4:*:*:*:*:*:*:* | |
| Vendors & Products |
Part-db Project
Part-db Project part-db |
Tue, 24 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Part-db
Part-db part-db |
|
| Vendors & Products |
Part-db
Part-db part-db |
Fri, 20 Feb 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Part-DB 0.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to login by injecting SQL syntax into authentication parameters. Attackers can submit a single quote followed by 'or' in the login form to bypass credential validation and gain unauthorized access to the application. | |
| Title | Part-DB 0.4 Authentication Bypass via login.php | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-02-20T22:54:46.521Z
Updated: 2026-03-05T01:26:42.489Z
Reserved: 2026-02-19T22:12:23.148Z
Link: CVE-2019-25432
Updated: 2026-02-24T15:23:35.489Z
Status : Awaiting Analysis
Published: 2026-02-20T23:15:59.840
Modified: 2026-02-23T18:14:13.887
Link: CVE-2019-25432
No data.