
Intentionally vulnerable PHP web app demonstrating SQL injection authentication bypass and unauthorized data disclosure modeled after CVE-2024-8465 for educational PoC and security testing.
Team Name: The Misfits
Team Members:
This repository contains a vulnerable web application created as a Proof of Concept (PoC) to demonstrate an SQL Injection vulnerability modeled after CVE-2024-8465.
The application is intentionally insecure and shows how improper input handling can lead to authentication bypass and database data disclosure.
This project is for academic and educational purposes only.
https://www.cve.org/CVERecord?id=CVE-2024-8465
File: login.php
Vulnerable SQL Query: SELECT id, username, role FROM users WHERE username='$username' AND password='$password'
Example Injection Payload: ' OR '1'='1' --
Impact: An attacker can bypass authentication and log in without valid credentials.
File: search.php
Vulnerable SQL Query: SELECT id, name, email, salary FROM employees WHERE name LIKE '%$q%'
Example Injection Payload: %' OR '1'='1' --
Impact: An attacker can retrieve all employee records including sensitive data.
Requirements:
Clone the repository: git clone https://github.com/19melek19/TheMisfits-CVE-2024-8465-SQLi.git
Navigate into the project directory: cd TheMisfits-CVE-2024-8465-SQLi
Start the vulnerable environment(We recommend that you use the terminal in Docker Desktop): docker compose up --build
Login Page: http://localhost:8080/index.php
Search Page: http://localhost:8080/search.php
The demo shows:
A screen-recorded demonstration video is provided separately. YouTube link: https://youtu.be/AFfSEyZrUnw
This project is a representative vulnerable implementation inspired by CVE-2024-8465. It is not the original affected software.
This project contains intentional security vulnerabilities. Do not deploy this application in a production environment. The authors are not responsible for any misuse.