216.73.217.22

CVE-2024-57328

· Published 23/01/2025 22:15 · Modified 29/01/2025 13:52

Labels: CVE-2024-57328 2025-01-23CVE-2024-57328CWE-89[email protected]

Essential information

Published
23/01/2025 22:15
Modified
29/01/2025 13:52
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

A SQL Injection vulnerability exists in the login form of Online Food Ordering System v1.0. The vulnerability arises because the input fields username and password are not properly sanitized, allowing attackers to inject malicious SQL queries to bypass authentication and gain unauthorized access.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
projectworlds / online food ordering system cpe:2.3:a:projectworlds:online_food_ordering_system:1.0:*:*:*:*:*:*:*

References