PT-2022-12413 · Martdevelopers · Iresturant

P0Cas

·

Published

2022-01-25

·

Updated

2022-01-28

·

CVE-2021-45803

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MartDevelopers iResturant version 1.0
Description The issue arises from the lack of verification of the view parameter value when it is added to the SQL query during the viewing of reservations, leading to SQL Injection.
Recommendations For MartDevelopers iResturant version 1.0, consider restricting access to the SQL query functionality related to viewing reservations until a proper fix is implemented to verify the view parameter value. As a temporary workaround, avoid using the view parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-45803

Affected Products

Iresturant