Online Food Ordering System v1.0 - Multiple Unauthenticated SQL Injections (SQLi)
CVE-2023-45341

9.8CRITICAL

What is CVE-2023-45341?

The Online Food Ordering System v1.0 contains multiple Unauthenticated SQL Injection vulnerabilities. Specific to the '*_price' parameter within the routers/menu-router.php resource, this vulnerability arises due to a lack of input validation. Unsanitized characters can be transmitted directly to the database, potentially allowing attackers to manipulate or extract sensitive data without authentication. Proper validation and sanitization of user inputs are crucial to mitigating such security risks.

Affected Version(s)

Online Food Ordering System 1.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.