SQL Injection Vulnerability in Online Ordering System by Oretnom23
CVE-2022-30795
7.2HIGH
Key Information:
- Status
- Vendor
- CVE Published:
- 2 June 2022
What is CVE-2022-30795?
The Online Ordering System v1.0 by Oretnom23 is susceptible to SQL Injection attacks through the admin/editproductimage.php file. This weakness can be exploited by an attacker to execute arbitrary SQL queries, potentially allowing unauthorized access to data or manipulation of the database. It highlights the importance of secure coding practices and timely updates to mitigate such vulnerabilities.
