CVE-2023-45325: Online Food Ordering System v1.0 - Multiple Unauthenticated SQL Injections (SQLi)
Published Nov 2, 2023
·Updated
Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'address' parameter of the routers/add-users.php resource does not validate the characters received and they are sent unfiltered to the database.
Affected Software
1 affected component
Projectworlds Online Food Ordering System=1.0
Event History
Nov 2, 2023
CVE Published
01:12 PM
Data Sourced
01:12 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-45325?
The severity of CVE-2023-45325 is rated as critical with a CVSS score of 9.8.
2
What software version is affected by CVE-2023-45325?
Online Food Ordering System v1.0 is affected by CVE-2023-45325.
3
How does CVE-2023-45325 impact the 'address' parameter in the Online Food Ordering System?
CVE-2023-45325 impacts the 'address' parameter of the routers/add-users.php resource in the Online Food Ordering System by allowing unauthenticated SQL Injections.