SQL Injection Vulnerability in Online Pet Shop Web Application by oretnom23
CVE-2022-40933
Key Information:
- Vendor
- CVE Published:
- 22 September 2022
What is CVE-2022-40933?
The Online Pet Shop Web Application version 1.0 developed by oretnom23 is exposed to a SQL injection vulnerability. This flaw allows attackers to manipulate SQL queries through the 'delete_order' function, potentially leading to unauthorized access to sensitive data or disruptive actions on the database. The vulnerability is triggered via a specially crafted request to the 'Master.php' file, specifically at the URL parameter '/pet_shop/classes/Master.php?f=delete_order,id'. This oversight poses a significant risk to the security and integrity of user data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
