Multiple SQL Injection vulnerabilities in tourist5 Online-food-ordering-system 1.0.
Loading...
Loading...
Score 9.8 from GitHub Security Advisory (severity: CRITICAL) published 2023-01-20. NVD baseline CVSS 9.8; sources differ by 0.0.
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
Multiple SQL Injection vulnerabilities in tourist5 Online-food-ordering-system 1.0.
January 20, 2023
March 30, 2026
GitHub - tourist5/Online-food-ordering-system: How To Install - --------- 1. Create Database food. 2. Run food.sql script provided in sql folder. 3. Go to login.php and try out our application. Sample user credentials can be found in users & wallet_details table. Note - --------- 1. This is not ready for PRODUCTION. 2. The username and password of sample users are stored in table `users`. 3. Only Customers with "Verified" status can place orders using "Cash on Delivery" option. 4. By default a new customer gets 2000 coins in Wallet on signing up, and a fake Credit card number & CVV number is generated and stored in SQL Table "wallet_details" with corresponding new customer's ID. 5. Use that Card Number & CVV while placing an order, else order won't be successful or use "Cash on delivery" option. 6. What's lacking? Dynamic payment(real payment system) and error reporting lacks in this project. And also one might wish for showing corresponding food item's photo and all that stuff. · GitHub
https://github.com/tourist5/Online-food-ordering-systemMITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
Explore the affected products and dependency analysis for CVE-2020-29297
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.