PT-2025-3427 · Unknown · Online Food Ordering System

Fatih Tüzün

·

Published

2025-01-23

·

Updated

2025-01-29

·

CVE-2024-57328

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Online Food Ordering System version 1.0
Description A SQL Injection issue exists in the login form of the system. The issue arises because the input fields username and password are not properly sanitized, allowing attackers to inject malicious SQL queries to bypass authentication and gain unauthorized access.
Recommendations Online Food Ordering System version 1.0: Properly sanitize the username and password input fields to prevent SQL injection attacks. Ensure that all user input is validated and escaped to prevent malicious SQL queries from being executed.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-57328

Affected Products

Online Food Ordering System