Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9rv8-797j-7r85

Опубликовано: 23 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

SQL Injection vulnerability in the /api/integrations/getintegrations endpoint of Order Up Online Ordering System 1.0 allows an unauthenticated attacker to access sensitive backend database data via a crafted store_id parameter in a POST request.

SQL Injection vulnerability in the /api/integrations/getintegrations endpoint of Order Up Online Ordering System 1.0 allows an unauthenticated attacker to access sensitive backend database data via a crafted store_id parameter in a POST request.

EPSS

Процентиль: 28%
0.00364
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
4 месяца назад

SQL Injection vulnerability in the /api/integrations/getintegrations endpoint of Order Up Online Ordering System 1.0 allows an unauthenticated attacker to access sensitive backend database data via a crafted store_id parameter in a POST request.

EPSS

Процентиль: 28%
0.00364
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89