Vulnerabilities (CVE)

Filtered by vendor Projectworlds Subscribe
Filtered by product Online Food Ordering System
Total 9 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-45344 1 Projectworlds 1 Online Food Ordering System 2024-11-21 N/A 9.8 CRITICAL
Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_balance' parameter of the routers/user-router.php resource does not validate the characters received and they are sent unfiltered to the database.
CVE-2023-45343 1 Projectworlds 1 Online Food Ordering System 2024-11-21 N/A 9.8 CRITICAL
Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'ticket_id' parameter of the routers/ticket-message.php resource does not validate the characters received and they are sent unfiltered to the database.
CVE-2023-45342 1 Projectworlds 1 Online Food Ordering System 2024-11-21 N/A 9.8 CRITICAL
Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'phone' parameter of the routers/register-router.php resource does not validate the characters received and they are sent unfiltered to the database.
CVE-2023-45341 1 Projectworlds 1 Online Food Ordering System 2024-11-21 N/A 9.8 CRITICAL
Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_price' parameter of the routers/menu-router.php resource does not validate the characters received and they are sent unfiltered to the database.
CVE-2023-45340 1 Projectworlds 1 Online Food Ordering System 2024-11-21 N/A 9.8 CRITICAL
Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'phone' parameter of the routers/details-router.php resource does not validate the characters received and they are sent unfiltered to the database.
CVE-2023-45336 1 Projectworlds 1 Online Food Ordering System 2024-11-21 N/A 9.8 CRITICAL
Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'password' parameter of the routers/router.php resource does not validate the characters received and they are sent unfiltered to the database.
CVE-2023-45334 1 Projectworlds 1 Online Food Ordering System 2024-11-21 N/A 9.8 CRITICAL
Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'status' parameter of the routers/edit-orders.php resource does not validate the characters received and they are sent unfiltered to the database.
CVE-2023-45325 1 Projectworlds 1 Online Food Ordering System 2024-11-21 N/A 9.8 CRITICAL
Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'address' parameter of the routers/add-users.php resource does not validate the characters received and they are sent unfiltered to the database.
CVE-2023-45323 1 Projectworlds 1 Online Food Ordering System 2024-11-21 N/A 9.8 CRITICAL
Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'name' parameter of the routers/add-item.php resource does not validate the characters received and they are sent unfiltered to the database.