Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-55721
HistoryJun 09, 2022 - 12:00 a.m.

Online Ordering System SQL Injection Vulnerability (CNVD-2022-55721)

2022-06-0900:00:00
China National Vulnerability Database
www.cnvd.org.cn
14
online ordering system
sql injection
version 2.3.2
validation
external input
attackers
sensitive data
database

EPSS

0.002

Percentile

54.5%

Online Ordering System is a multi-store ordering system that can be used by any small business.Online Ordering System version 2.3.2 is vulnerable to a SQL injection vulnerability that originates in /ordering/index.php?q=products&id=The page lacks validation for external input SQL statements, which can be exploited by attackers to execute illegal SQL commands to steal sensitive database data.

EPSS

0.002

Percentile

54.5%

Related for CNVD-2022-55721