CVE-2023-45341: Online Food Ordering System v1.0 - Multiple Unauthenticated SQL Injections (SQLi)
Published Nov 2, 2023
·Updated
Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'price' parameter of the routers/menu-router.php resource does not validate the characters received and they are sent unfiltered to the database.
Affected Software
1 affected component
Projectworlds Online Food Ordering System=1.0
Event History
Nov 2, 2023
CVE Published
01:58 PM
Data Sourced
01:58 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2023-45341.
2
What is the severity of CVE-2023-45341?
The severity of CVE-2023-45341 is critical with a CVSS score of 9.8.
3
What is the affected software?
The affected software is Online Food Ordering System v1.0 by Online Food Ordering Script Project.
4
What is the CWE ID of this vulnerability?
The CWE ID of this vulnerability is CWE-89.
5
How can I fix CVE-2023-45341?
To fix CVE-2023-45341, update Online Food Ordering System to a version that has fixed the multiple unauthenticated SQL injection vulnerabilities.