PT-2025-15110 · Unknown · Codeprojects Online Restaurant Management System

Pyj2Cve

·

Published

2025-04-06

·

Updated

2025-04-07

·

CVE-2025-3340

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions codeprojects Online Restaurant Management System version 1.0
Description A critical issue has been found in the codeprojects Online Restaurant Management System, affecting some unknown functionality of the file /admin/combo update.php. The manipulation of the ID argument leads to SQL injection. The attack can be launched remotely.
Recommendations For codeprojects Online Restaurant Management System version 1.0, consider restricting access to the /admin/combo update.php file and avoid using the ID argument in this context until a fix is available. As a temporary workaround, consider implementing input validation and sanitization for the ID argument to minimize the risk of SQL injection exploitation.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-3340

Affected Products

Codeprojects Online Restaurant Management System