Restaurant Order System SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability has been identified in Restaurant Order System version 1.0. This vulnerability allows local attackers to access sensitive information through the payment.php file.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information stored in the application's database.

Reproduction

To reproduce this vulnerability, send a crafted GET request to the payment.php file. Include a SQL injection payload that exploits the application's SQL query handling. The payload should be designed to extract data from the database, such as using a UNION SELECT injection to retrieve information from other tables.

Added: Aug 1, 2025, 4:37 PM
Updated: Aug 1, 2025, 4:37 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.6
remediation
0.0
relevance
0.3
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.