CVE-2022-31336: SQL Injection
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/loaddata.php.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-31336?
CVE-2022-31336 is a SQL Injection vulnerability in Online Ordering System version 2.3.2.
How severe is CVE-2022-31336?
CVE-2022-31336 has a severity rating of 9.8 (Critical).
How does CVE-2022-31336 affect Online Ordering System?
CVE-2022-31336 affects Online Ordering System version 2.3.2 and allows an attacker to perform SQL injection attacks via the /ordering/admin/stockin/loaddata.php endpoint.
How can I fix CVE-2022-31336 in Online Ordering System?
To fix CVE-2022-31336, it is recommended to update Online Ordering System to a version that is not affected by the vulnerability or apply a patch provided by the vendor.
Where can I find more information about CVE-2022-31336?
You can find more information about CVE-2022-31336 at the following reference: https://github.com/k0xx11/bug_report/blob/main/vendors/janobe/online-ordering-system/SQLi-7.md