SQL Injection Vulnerability in Online Ordering System by Janobe
CVE-2022-31355
9.8CRITICAL
Key Information:
- Status
- Vendor
- CVE Published:
- 17 June 2022
What is CVE-2022-31355?
The Online Ordering System version 2.3.2 is susceptible to a SQL injection vulnerability through the endpoint /ordering/index.php?q=category&search=. This security flaw could potentially allow attackers to manipulate SQL queries, leading to unauthorized access to sensitive data and further exploitation of the system.
