CVE-2022-31356: SQL Injection
Published Jun 17, 2022
·Updated
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/store/index.php?view=edit&id=.
Affected Software
1 affected component
Online Ordering System Project Online Ordering System=2.3.2
Event History
Jun 17, 2022
CVE Published
via MITRE·01:29 PM
Data Sourced
via MITRE·01:29 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-31356?
CVE-2022-31356 has a high severity due to its potential to allow SQL injection attacks.
2
How do I fix CVE-2022-31356?
To fix CVE-2022-31356, you should upgrade to the latest version of online Ordering System which addresses the SQL injection vulnerability.
3
What impact does CVE-2022-31356 have?
CVE-2022-31356 can lead to unauthorized access to sensitive data in the database via SQL injection.
4
What software versions are affected by CVE-2022-31356?
CVE-2022-31356 specifically affects Online Ordering System version 2.3.2.
5
How can I identify if my system is vulnerable to CVE-2022-31356?
You can identify if your system is vulnerable to CVE-2022-31356 by checking for the specific URL parameters that expose the SQL injection flaw.