Online Food Ordering System v1.0 - Multiple Unauthenticated SQL Injections (SQLi)
CVE-2023-45346
9.8CRITICAL
What is CVE-2023-45346?
The Online Food Ordering System v1.0 by Project Worlds is exposed to multiple Unauthenticated SQL Injection vulnerabilities. The vulnerability arises from the improper validation of the '*_role' parameter within the routers/user-router.php resource. This flaw allows an attacker to send unfiltered input directly to the database, potentially compromising sensitive data and system integrity.
Affected Version(s)
Online Food Ordering System 1.0