Unknown · Online Ordering System · CVE-2022-31355
**Name of the Vulnerable Software and Affected Versions**
Online Ordering System version 2.3.2
**Description**
The issue is related to a SQL injection vulnerability. It can be exploited via the "/ordering/index.php?q=category&search=" API endpoint. The `search` parameter is vulnerable.
**Recommendations**
For Online Ordering System version 2.3.2, as a temporary workaround, consider restricting access to the "/ordering/index.php?q=category&search=" endpoint until a patch is available. Avoid using the `search` parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.