Vulnerability Description
MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because the email and phone parameter values are added to the SQL query without any verification at the time of membership registration.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Iresturant Project | Iresturant | 1.0 |
Related Weaknesses (CWE)
References
- https://blog.pocas.kr/posts/sqli-iResturant/Broken Link
- https://gist.github.com/P0cas/5aa55f62781364a750ac4a4d47f319fa#file-cve-2021-458ExploitThird Party Advisory
- https://blog.pocas.kr/posts/sqli-iResturant/Broken Link
- https://gist.github.com/P0cas/5aa55f62781364a750ac4a4d47f319fa#file-cve-2021-458ExploitThird Party Advisory
FAQ
What is CVE-2021-45802?
CVE-2021-45802 is a vulnerability with a CVSS score of 9.8 (CRITICAL). MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because the email and phone parameter values are added to the SQL query without any verification at the time of membe...
How severe is CVE-2021-45802?
CVE-2021-45802 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-45802?
Check the references section above for vendor advisories and patch information. Affected products include: Iresturant Project Iresturant.