CVE-2022-31329: SQL Injection
Published May 31, 2022
·Updated
Online Ordering System By janobe 2.3.2 is vulnerable to SQL Injection via /ordering/admin/orders/loaddata.php.
Affected Software
1 affected component
Online Ordering System Project Online Ordering System=2.3.2
Event History
May 31, 2022
CVE Published
via MITRE·03:27 PM
Data Sourced
via MITRE·03:27 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-31329?
CVE-2022-31329 is classified as a high severity vulnerability due to its potential to allow unauthorized database access.
2
How do I fix CVE-2022-31329?
To fix CVE-2022-31329, apply input validation and parameterized queries to prevent SQL injection.
3
What are the potential impacts of CVE-2022-31329?
The potential impacts of CVE-2022-31329 include data theft, data manipulation, and unauthorized administrative access.
4
Is CVE-2022-31329 exploitable remotely?
Yes, CVE-2022-31329 is exploitable remotely through the vulnerable endpoint exposed in the application.
5
Which versions are affected by CVE-2022-31329?
CVE-2022-31329 affects version 2.3.2 of the Online Ordering System by janobe.