CVE-2021-28295

Online Ordering System 1.0 is vulnerable to unauthenticated SQL injection through /onlineordering/GPST/admin/design.php, which may lead to database information disclosure.

Summary:

Online Ordering System 1.0 is vulnerable to unauthenticated SQL injection through /onlineordering/GPST/admin/design.php, which may lead to database information disclosure.

Reference Links(if available):

  • https://www.exploit-db.com/exploits/49618
  • CVSS Score (if available)

    v2: / MEDIUM

    v3: /

    Links to Exploits(if available)