Online Food Ordering System v1.0 - Multiple Unauthenticated SQL Injections (SQLi)
CVE-2023-45341
9.8CRITICAL
What is CVE-2023-45341?
The Online Food Ordering System v1.0 contains multiple Unauthenticated SQL Injection vulnerabilities. Specific to the '*_price' parameter within the routers/menu-router.php resource, this vulnerability arises due to a lack of input validation. Unsanitized characters can be transmitted directly to the database, potentially allowing attackers to manipulate or extract sensitive data without authentication. Proper validation and sanitization of user inputs are crucial to mitigating such security risks.
Affected Version(s)
Online Food Ordering System 1.0