Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-55711
HistoryJun 21, 2022 - 12:00 a.m.

Online Ordering System SQL Injection Vulnerability (CNVD-2022-55711)

2022-06-2100:00:00
China National Vulnerability Database
www.cnvd.org.cn
13
online ordering system
multi-store
sql injection
validation
sensitive data

EPSS

0.002

Percentile

54.5%

Online Ordering System is a multi-store ordering system that can be used by any small business.Online Ordering System version v2.3.2 is vulnerable to SQL injection, which originates from /ordering/index.php?q=category&search=Lack of validation of external input SQL statement validation, an attacker can use this vulnerability to execute illegal SQL commands to steal sensitive database data.

EPSS

0.002

Percentile

54.5%

Related for CNVD-2022-55711