First published: Sun Jan 15 2023(Updated: )
A vulnerability classified as critical was found in SourceCodester Online Food Ordering System. This vulnerability affects unknown code of the file admin_class.php of the component Login Module. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-218386 is the identifier assigned to this vulnerability.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Online Food Ordering System v2 project Online Food Ordering System v2 | ||
Online Food Ordering System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0305 is classified as a critical vulnerability.
To fix CVE-2023-0305, it's recommended to validate and sanitize all user inputs, especially the username parameter, to prevent SQL injection.
CVE-2023-0305 affects the Login Module code in the admin_class.php file of the Online Food Ordering System.
CVE-2023-0305 can be exploited through SQL injection attacks due to improper handling of the username argument.
CVE-2023-0305 affects all unspecified versions of the Online Food Ordering System v2 project.