SourceCodester Online Food Ordering System manage_user.php sql injection
CVE-2023-0332

9.8CRITICAL

Key Information:

Vendor
CVE Published:
17 January 2023

Summary

An SQL injection vulnerability exists in the management functionality of SourceCodester's online food ordering system. The flaw resides in 'admin/manage_user.php', allowing attackers to manipulate the 'id' parameter and execute unauthorized SQL commands. This type of exploit can be executed remotely, posing a significant security risk to organizations utilizing this software. The vulnerability has been made public, increasing the likelihood of potential attacks.

Affected Version(s)

Online Food Ordering System 2.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Geccccc (VulDB User)
.