Order Up Online Ordering System SQL Injection Vulnerability in Integrations API Endpoint
Vulnerability
A SQL injection vulnerability has been identified in the Order Up Online Ordering System version 1.0. The issue resides in the '/api/integrations/getintegrations' endpoint, where an unauthenticated attacker can exploit a crafted 'store_id' parameter in a POST request to access sensitive backend database information.
Impact
Exploitation of this vulnerability allows for unauthorized access to sensitive database information, potentially leading to data leakage or manipulation.
Added: Feb 23, 2026, 2:17 AM
Updated: Feb 23, 2026, 2:17 AM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
2.5exploitability
7.4remediation
0.0relevance
3.1threat
0.0urgency
2.9incentive
4.2Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
