CVE-2021-28295: SQL Injection
Published Mar 16, 2021
·Updated
Online Ordering System 1.0 is vulnerable to unauthenticated SQL injection through /onlineordering/GPST/admin/design.php, which may lead to database information disclosure.
Affected Software
1 affected component
Online Ordering System Project Online Ordering System=1.0
Event History
Mar 16, 2021
CVE Published
via MITRE·07:54 PM
Data Sourced
via MITRE·07:54 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-28295?
CVE-2021-28295 is classified as a high severity vulnerability due to the potential for unauthorized database access.
2
How do I fix CVE-2021-28295?
To fix CVE-2021-28295, update your Online Ordering System to the latest version that addresses this SQL injection vulnerability.
3
What impact does CVE-2021-28295 have on my system?
CVE-2021-28295 can lead to unauthorized access and disclosure of sensitive database information.
4
What is the nature of the vulnerability in CVE-2021-28295?
CVE-2021-28295 is an unauthenticated SQL injection vulnerability that allows attackers to manipulate database queries.
5
Is my version of the Online Ordering System affected by CVE-2021-28295?
Yes, Online Ordering System version 1.0 is specifically affected by CVE-2021-28295.