🚨 What just happened
The password you entered didn't match anything — but you still got in. That's because the
login "backend" builds its database query like this, by pasting your input straight into the SQL string:
Query built from your input
Your input included a stray quote and the text OR '1'='1'. That closes the
string early and adds a condition that's always true, so the WHERE clause matches
the first row in the table regardless of password — in this case, the admin account.
❌ Vulnerable
"SELECT * FROM users WHERE
username='" + user + "'
AND password='" + pass + "'"
✅ Fixed (parameterized)
"SELECT * FROM users WHERE
username = ? AND password = ?"
db.execute(query, [user, pass])
Parameterized queries send your input as data, never as part of
the SQL itself — so a quote in the username field is just a literal character, not a way to
rewrite the query.