Online Food Ordering System v1.0 - Multiple Unauthenticated SQL Injections (SQLi)
CVE-2023-45347
9.8CRITICAL
What is CVE-2023-45347?
The Online Food Ordering System version 1.0 is susceptible to multiple SQL injection vulnerabilities due to inadequate validation of the '*_verified' parameter in the routers/user-router.php resource. This flaw allows attackers to send unfiltered input to the database, which can lead to unauthorized access and manipulation of sensitive information.
Affected Version(s)
Online Food Ordering System 1.0