Online Food Ordering System v1.0 - Multiple Unauthenticated SQL Injections (SQLi)
CVE-2023-45336
9.8CRITICAL
What is CVE-2023-45336?
The Online Food Ordering System version 1.0 has multiple vulnerabilities pertaining to SQL Injection that allow an attacker to execute unauthorized SQL commands through the 'password' parameter in the routers/router.php resource. This issue arises due to inadequate validation of user input, enabling potential data breaches and manipulation of the database.
Affected Version(s)
Online Food Ordering System 1.0