Description


A vulnerability was found in code-projects Restaurant Reservation System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /addcompany.php. The manipulation of the argument company leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

References



https://github.com/ppp-src/a/issues/22

ExploitThird Party Advisory

https://vuldb.com/?ctiid.278888

Permissions RequiredThird Party AdvisoryVDB Entry

https://vuldb.com/?id.278888

Third Party AdvisoryVDB Entry

https://vuldb.com/?submit.416041

Third Party AdvisoryVDB Entry

Weaknesses



CWE-89

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.8 · Critical

  • CVSS V3.1

  • CVSS V3.0

  • CVSS V2.0

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2024-10-01T02:15:10.657

1 week ago

Last modified

2024-10-04T18:54:12.417

4 days ago