Blind SQL Injection Vulnerability in Multi-Vendor Online Groceries Management System by Multiple Vendors
CVE-2022-26632
9.8CRITICAL
Key Information:
- Vendor
- CVE Published:
- 20 May 2022
What is CVE-2022-26632?
A blind SQL injection vulnerability has been identified in version 1.0 of the Multi-Vendor Online Groceries Management System. The flaw arises through the id parameter in the /products/view_product.php file, enabling an attacker to manipulate database queries without directly seeing the results. This can lead to unauthorized data access and manipulation, posing a significant security risk to the application and its users.