RSS   Vulnerabilities for 'Fast food ordering system'   RSS

2022-07-14
 
CVE-2022-32318

CWE-79
 

 
Fast Food Ordering System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via the component /ffos/classes/Master.php?f=save_category.

 
2022-06-14
 
CVE-2022-32328

CWE-668
 

 
Fast Food Ordering System v1.0 is vulnerable to Delete any file. via /ffos/classes/Master.php?f=delete_img.

 
 
CVE-2022-32330

CWE-89
 

 
Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/classes/Master.php?f=delete_menu.

 
 
CVE-2022-32331

CWE-89
 

 
Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/categories/view_category.php?id=.

 
 
CVE-2022-32332

CWE-89
 

 
Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/classes/Master.php?f=delete_category.

 
 
CVE-2022-32333

CWE-89
 

 
Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/sales/receipt.php?id=.

 
 
CVE-2022-32334

CWE-89
 

 
Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/categories/manage_category.php?id=.

 
 
CVE-2022-32335

CWE-89
 

 
Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/menus/manage_menu.php?id=.

 
 
CVE-2022-32336

CWE-89
 

 
Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/menus/view_menu.php?id=.

 
2022-06-07
 
CVE-2022-1991

CWE-79
 

 
A vulnerability classified as problematic has been found in Fast Food Ordering System 1.0. Affected is the file Master.php of the Master List. The manipulation of the argument Description with the input foo "><img src="" onerror="alert(document.cookie)"> leads to cross site scripting. It is possible to launch the attack remotely but it requires authentication. Exploit details have been disclosed to the public.

 


Copyright 2024, cxsecurity.com

 

Back to Top