FixVibe

critical

Authentication Bypass via SQL Injection in Sourcecodetester Daily Tracker System 1.0 (CVE-2020-24193)

Daily Tracker System 1.0 has a critical CVE-2020-24193 login SQL injection/authentication-bypass issue. FixVibe GitHub repo scans flag the vulnerable login source.

CVE-2020-24193CWE-89

Vulnerability Overview

Daily Tracker System 1.0 is associated with CVE-2020-24193, a critical login SQL injection issue. Public CVE records describe an unauthenticated authentication-bypass condition through login input that can alter the backend user lookup [S1][S2].

Attacker Impact

If the vulnerable login code is deployed unchanged, an unauthenticated attacker may be able to bypass authentication and gain access to the application as another user [S1][S2]. Impact depends on whether the affected Daily Tracker source is actually deployed, reachable, and connected to production data.

Root Cause

The vulnerable pattern is login code that builds a database query from posted login fields without parameter binding [S1][S3]. Input filtering alone is not a complete fix for SQL injection; the query must keep SQL text and untrusted values in separate channels.

Remediation

Replace the login database lookup with prepared statements or parameterized queries, using mysqli or PDO bind parameters. Remove the vulnerable sample application code if it is not part of the product, rebuild and redeploy from clean sources, and review authentication logs if this code was exposed [S1][S2].

How FixVibe covers it

FixVibe's GitHub repository scans flag Daily Tracker PHP login source with the unsafe SQL construction behind CVE-2020-24193 [S1][S2][S3], with the file and line to fix.