Description
An un-authenticated error-based and time-based blind SQL injection vulnerability exists in Kaushik Jadhav Online Food Ordering Web App 1.0. An attacker can exploit the vulnerable "username" parameter in login.php and retrieve sensitive database information, as well as add an administrative user.
Published: 2021-10-01
Score: 9.1 Critical
EPSS: 1.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-28659 An un-authenticated error-based and time-based blind SQL injection vulnerability exists in Kaushik Jadhav Online Food Ordering Web App 1.0. An attacker can exploit the vulnerable "username" parameter in login.php and retrieve sensitive database information, as well as add an administrative user.
History

No history.

Subscriptions

Online Food Ordering Web App Project Online Food Ordering Web App
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T03:15:29.215Z

Reserved: 2021-09-27T00:00:00.000Z

Link: CVE-2021-41647

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-10-01T15:15:07.947

Modified: 2024-11-21T06:26:34.390

Link: CVE-2021-41647

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses