CVE-2020-28994
Summary
| CVE | CVE-2020-28994 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-11-24 18:15:00 UTC |
| Updated | 2020-11-30 16:13:00 UTC |
| Description | A SQL injection vulnerability was discovered in Karenderia Multiple Restaurant System, affecting versions 5.4.2 and below. The vulnerability allows for an unauthenticated attacker to perform various tasks such as modifying and leaking all contents of the database. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Karenderia Multiple Restaurant System Project | Karenderia Multiple Restaurant System | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Karenderia Multiple Restaurant System v5.4.2 SQLi.md · GitHub | MISC | gist.github.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.