SQL Injection Vulnerability in Online Ordering System by Janobe
CVE-2022-31327
9.8CRITICAL
Key Information:
- Status
- Vendor
- CVE Published:
- 2 June 2022
What is CVE-2022-31327?
The Online Ordering System by Janobe version 2.3.2 contains a vulnerability that allows an attacker to execute SQL injection through manipulated input parameters in the URL, specifically via the '/ordering/index.php?q=products&id=' endpoint. This flaw can potentially allow unauthorized access to the backend database, leading to data leakage and manipulation. Proper sanitation and validation of user input are crucial to mitigate this risk.
