PT-2022-12412 · Martdevelopers · Iresturant

P0Cas

·

Published

2022-01-25

·

Updated

2022-01-28

·

CVE-2021-45802

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MartDevelopers iResturant version 1.0
Description The issue arises from the lack of verification of email and phone parameter values, which are directly added to the SQL query during membership registration, leading to SQL Injection.
Recommendations For MartDevelopers iResturant version 1.0, ensure that the email and phone parameter values are properly verified and sanitized before adding them to the SQL query to prevent SQL Injection. As a temporary workaround, consider implementing input validation for the email and phone parameters to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-45802

Affected Products

Iresturant