SQL Injection Vulnerability in Online Ordering System by Janobe
CVE-2022-31336
9.8CRITICAL
Key Information:
- Status
- Vendor
- CVE Published:
- 31 May 2022
What is CVE-2022-31336?
Version 2.3.2 of the Online Ordering System by Janobe is susceptible to SQL Injection attacks through the endpoint /ordering/admin/stockin/loaddata.php. This vulnerability could allow an attacker to manipulate SQL queries and retrieve sensitive information from the database, compromising the integrity and confidentiality of the system.
