« Volver al listado

Iresturant Project

Iresturant Project Iresturant: vulnerabilidades y CVE

Iresturant Project Iresturant tiene 5 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE5
Últimos 12 meses0
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2021-45803Alta (8.8)1.2%—25 ene 2022
MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because this view parameter value is added to the SQL query without additional verification when viewing reservation.
CVE-2021-45802Crítica (9.8)1.3%—25 ene 2022
MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because the email and phone parameter values are added to the SQL query without any verification at the time of membership registration.
CVE-2021-43436Media (5.4)0.59%—12 ene 2022
MartDevelopers Inc iResturant v1.0 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of failed logins, the XSS payload will be executed.
CVE-2021-43439Crítica (9.8)3.4%—20 dic 2021
RCE in Add Review Function in iResturant 1.0 Allows remote attacker to execute commands remotely
CVE-2021-43438Media (5.4)0.66%—20 dic 2021
Stored XSS in Signup Form in iResturant 1.0 Allows Remote Attacker to Inject Arbitrary code via NAME and ADDRESS field