🎯 Security Flaws on this page:
- Simulated SQL Injection Bypass: Enter
' OR 1=1 --or' OR '1'='1into the username field to bypass credentials and log in as the Administrator. - URL Authentication Bypass: Adding
?bypass=true&role=adminto the URL instantly signs you in as root admin! - Reflected XSS in Error Handler: URL error parameters like
?error=<img src=x onerror=alert('Login-XSS')>render unescaped directly in the DOM. - Plaintext Credentials Exposure: Hardcoded accounts and passwords stored unhashed in local storage.
Account Login
Sign in to manage your orders and profile
Demo Lab Accounts:
•
admin / adminpassword123 (Administrator)•
alice / password123 (Customer)•
bob / bobsecretpassword (Customer)