WHMCompleteSolution (WHMCS) contains a flaw in the admin/login php script. The issue is triggered when parsing POST_SESSION requests. This may allow a remote attacker to bypass authentication.
after
you have successfully entered that into your browser, the page will lag
for abit due to the cache-validation, which we, ofcourse, will change
it. ;-)
when the page is loading, quickly open Tamper Data and change the loading POST_SESSION request & the payload to this: