CVE-2022-31337: SQL Injection
Published May 31, 2022
·Updated
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/category/index.php?view=edit&id=.
Affected Software
1 affected component
Online Ordering System Project Online Ordering System=2.3.2
Event History
May 31, 2022
CVE Published
via MITRE·02:54 PM
Data Sourced
via MITRE·02:54 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-31337?
CVE-2022-31337 is classified as a high severity vulnerability due to its potential for SQL Injection attacks.
2
How do I fix CVE-2022-31337?
To fix CVE-2022-31337, ensure you sanitize and validate user input, particularly for the 'id' parameter, and apply updates if available.
3
What type of vulnerability is CVE-2022-31337?
CVE-2022-31337 is an SQL Injection vulnerability affecting the Online Ordering System.
4
What software versions are affected by CVE-2022-31337?
Only Online Ordering System version 2.3.2 is affected by CVE-2022-31337.
5
Can CVE-2022-31337 lead to data compromise?
Yes, exploitation of CVE-2022-31337 can lead to unauthorized access to the database and potential data compromise.