Vulnerability CVE-2023-45341


Published: 2023-11-02

Description:
Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_price' parameter of the routers/menu-router.php resource does not validate the characters received and they are sent unfiltered to the database.

Type:

CWE-89

(Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'))

 References:
https://projectworlds.in/
https://fluidattacks.com/advisories/hann

Copyright 2026, cxsecurity.com

 

Back to Top