Order Up Online Ordering System SQL Injection Vulnerability in Integrations API Endpoint

Vulnerability

A SQL injection vulnerability has been identified in the Order Up Online Ordering System version 1.0. The issue resides in the '/api/integrations/getintegrations' endpoint, where an unauthenticated attacker can exploit a crafted 'store_id' parameter in a POST request to access sensitive backend database information.

Impact

Exploitation of this vulnerability allows for unauthorized access to sensitive database information, potentially leading to data leakage or manipulation.

Added: Feb 23, 2026, 2:17 AM
Updated: Feb 23, 2026, 2:17 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
3.1
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.