PT-2021-23366 · Unknown · Kaushik Jadhav Online Food Ordering Web App

Jason Colyvas

·

Published

2021-10-01

·

Updated

2021-10-08

·

CVE-2021-41647

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Kaushik Jadhav Online Food Ordering Web App version 1.0
Description An un-authenticated error-based and time-based blind SQL injection issue exists. An attacker can exploit the vulnerable username parameter in "login.php" and retrieve sensitive database information, as well as add an administrative user.
Recommendations For Kaushik Jadhav Online Food Ordering Web App version 1.0, consider disabling the username parameter in the "login.php" file until a patch is available. Restrict access to the "login.php" file to minimize the risk of exploitation. Avoid using the username parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41647

Affected Products

Kaushik Jadhav Online Food Ordering Web App