SourceCodester Online Food Ordering System manage_user.php sql injection
CVE-2023-0332
9.8CRITICAL
Summary
An SQL injection vulnerability exists in the management functionality of SourceCodester's online food ordering system. The flaw resides in 'admin/manage_user.php', allowing attackers to manipulate the 'id' parameter and execute unauthorized SQL commands. This type of exploit can be executed remotely, posing a significant security risk to organizations utilizing this software. The vulnerability has been made public, increasing the likelihood of potential attacks.
Affected Version(s)
Online Food Ordering System 2.0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Geccccc (VulDB User)