PoC Index

CVE-2024-57328

CRITICAL 9.8EPSS 0.6%

A SQL Injection vulnerability exists in the login form of Online Food Ordering System v1.0. The vulnerability arises because the input fields username and password are not properly sanitized, allowing attackers to inject malicious SQL queries to bypass authentication and gain unauthorized access.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
0.56% chance of exploitation in the next 30 days, 45th percentile
Published
2025-01-23
Updated
2025-01-24

Proof-of-concept exploits (1)

References

Related