CVE-2024-13070: CodeAstro Online Food Ordering System Update User Page update_users.php sql injection
A vulnerability was found in CodeAstro Online Food Ordering System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/updateusers.php of the component Update User Page. The manipulation of the argument userupd leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13070?
CVE-2024-13070 has been declared as a critical vulnerability.
What component is affected by CVE-2024-13070?
CVE-2024-13070 affects the Update User Page found in /admin/update_users.php.
How do I fix CVE-2024-13070?
To fix CVE-2024-13070, ensure that any user input for the user_upd argument is properly validated and sanitized.
What software is impacted by CVE-2024-13070?
CVE-2024-13070 impacts the CodeAstro Online Food Ordering System version 1.0.
What type of vulnerability is CVE-2024-13070?
CVE-2024-13070 is associated with improper input validation in a web application.