Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-55716
HistoryJun 09, 2022 - 12:00 a.m.

Online Ordering System SQL Injection Vulnerability (CNVD-2022-55716)

2022-06-0900:00:00
China National Vulnerability Database
www.cnvd.org.cn
14
online ordering system
sql injection
vulnerability
lack of validation
admin page
exploit

EPSS

0.001

Percentile

37.7%

Online Ordering System is a multi-store ordering system that can be used by any small business. version 1.0 of Online Ordering System is vulnerable to a SQL injection vulnerability that stems from a lack of validation of externally entered SQL statements on the admin/editproductimage.php page, which could be used by an attacker to exploit this vulnerability to execute illegal SQL commands to steal sensitive database data.

EPSS

0.001

Percentile

37.7%

Related for CNVD-2022-55716