SQL Injection Vulnerability in Online Ordering System by Janobe
CVE-2022-31335
9.8CRITICAL
Key Information:
- Status
- Vendor
- CVE Published:
- 2 June 2022
What is CVE-2022-31335?
The Online Ordering System version 2.3.2 from Janobe is affected by a SQL injection vulnerability found in the admin stock management interface. This flaw allows an unauthorized attacker to manipulate SQL queries by crafting a malicious request to the index.php file, specifically at the 'view=edit&id=' parameter. Successful exploitation of this vulnerability could lead to the exposure of sensitive data or potential manipulation of the database.
