SQL Injection Vulnerability in Online Ordering System by Janobe
CVE-2022-31327

9.8CRITICAL

What is CVE-2022-31327?

The Online Ordering System by Janobe version 2.3.2 contains a vulnerability that allows an attacker to execute SQL injection through manipulated input parameters in the URL, specifically via the '/ordering/index.php?q=products&id=' endpoint. This flaw can potentially allow unauthorized access to the backend database, leading to data leakage and manipulation. Proper sanitation and validation of user input are crucial to mitigate this risk.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.