CVE-2022-31335: SQL Injection
Published May 31, 2022
·Updated
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/index.php?view=edit&id=.
Affected Software
1 affected component
Online Ordering System Project Online Ordering System=2.3.2
Event History
May 31, 2022
CVE Published
via MITRE·02:58 PM
Data Sourced
via MITRE·02:58 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-31335?
The severity of CVE-2022-31335 is critical (9.8).
2
How does CVE-2022-31335 affect Online Ordering System 2.3.2?
CVE-2022-31335 allows SQL Injection in Online Ordering System 2.3.2 via the /ordering/admin/stockin/index.php?view=edit&id= parameter.
3
How can I fix CVE-2022-31335 in Online Ordering System 2.3.2?
To fix CVE-2022-31335, it is recommended to update Online Ordering System to a version that addresses the SQL Injection vulnerability.
4
What is the CWE of CVE-2022-31335?
The CWE of CVE-2022-31335 is CWE-89 (SQL Injection).
5
Where can I find more information about CVE-2022-31335?
You can find more information about CVE-2022-31335 at the following reference: [CVE-2022-31335](https://github.com/k0xx11/bug_report/blob/main/vendors/janobe/online-ordering-system/SQLi-6.md).