Part-DB 0.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to login by injecting SQL syntax into authentication parameters. Attackers can submit a single quote followed by 'or' in the login form to bypass credential validation and gain unauthorized access to the application.
Metrics
Affected Vendors & Products
References
History
Fri, 20 Feb 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Part-DB 0.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to login by injecting SQL syntax into authentication parameters. Attackers can submit a single quote followed by 'or' in the login form to bypass credential validation and gain unauthorized access to the application. | |
| Title | Part-DB 0.4 Authentication Bypass via login.php | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-02-20T22:54:46.521Z
Updated: 2026-02-20T22:54:46.521Z
Reserved: 2026-02-19T22:12:23.148Z
Link: CVE-2019-25432
No data.
Status : Received
Published: 2026-02-20T23:15:59.840
Modified: 2026-02-20T23:15:59.840
Link: CVE-2019-25432
No data.