CVE-2023-5014
Published on: Not Yet Published
Last Modified on: 09/20/2023 01:27:00 PM UTC
Certain versions of Food Ordering Website from Food Ordering Website Project contain the following vulnerability:
A vulnerability was found in Sakshi2610 Food Ordering Website 1.0 and classified as critical. This issue affects some unknown processing of the file categoryfood.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-239855.
- CVE-2023-5014 has been assigned by
[email protected] to track the vulnerability - currently rated as CRITICAL severity.
- Affected Vendor/Software:
Sakshi2610 - Food Ordering Website version = 1.0
CVSS3 Score: 9.8 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Login required | vuldb.com text/html Inactive LinkNot Archived |
![]() |
Food Ordering Website 1.0 has a SQL injection vulnerability in categoryfood.php | github.com text/plain |
![]() |
CVE-2023-5014: Sakshi2610 Food Ordering Website categoryfood.php sql injection | vuldb.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Food Ordering Website Project | Food Ordering Website | 1.0 | All | All | All |
- cpe:2.3:a:food_ordering_website_project:food_ordering_website:1.0:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE