PT-2022-12412 · Martdevelopers · Iresturant
P0Cas
·
Published
2022-01-25
·
Updated
2022-01-28
·
CVE-2021-45802
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MartDevelopers iResturant version 1.0
Description
The issue arises from the lack of verification of
email and phone parameter values, which are directly added to the SQL query during membership registration, leading to SQL Injection.Recommendations
For MartDevelopers iResturant version 1.0, ensure that the
email and phone parameter values are properly verified and sanitized before adding them to the SQL query to prevent SQL Injection. As a temporary workaround, consider implementing input validation for the email and phone parameters to minimize the risk of exploitation.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Iresturant