← Back

Online Ordering System Project

online_ordering_system_project

21 CVEs • 1 product

Products (1)

Click to collapse
Toggle

CVEs (21)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Online Ordering System Project
1Online Ordering System
Apr 29, 2026
Jul 17, 2025
2.1 LOW· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability was found in code-projects Online Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/edit_product.php. The manipulation of the argument image...Show more
A vulnerability was found in code-projects Online Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/edit_product.php. The manipulation of the argument image leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.Show less
1Online Ordering System Project
1Online Ordering System
Nov 21, 2024
Aug 31, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via the user_email parameter at /admin/login.php.
1Online Ordering System Project
1Online Ordering System
Nov 21, 2024
Aug 31, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
An arbitrary file upload vulnerability in the component /admin/products/controller.php?action=add of Online Ordering System v2.3.2 allows attackers to execute arbitrary code via a crafted PHP file.
1Online Ordering System Project
1Online Ordering System
Nov 21, 2024
Jun 17, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/inventory/index.php?view=edit&id=.
1Online Ordering System Project
1Online Ordering System
Nov 21, 2024
Jun 17, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/store/index.php?view=edit&id=.
1Online Ordering System Project
1Online Ordering System
Nov 21, 2024
Jun 17, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/index.php?q=category&search=.
1Online Ordering System Project
1Online Ordering System
Nov 21, 2024
Jun 2, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/user/index.php?view=edit&id=.
1Online Ordering System Project
1Online Ordering System
Nov 21, 2024
Jun 2, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/category/index.php?view=edit&id=.
1Online Ordering System Project
1Online Ordering System
Nov 21, 2024
Jun 2, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/loaddata.php.
1Online Ordering System Project
1Online Ordering System
Nov 21, 2024
Jun 2, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/index.php?view=edit&id=.
1Online Ordering System Project
1Online Ordering System
Nov 21, 2024
Jun 2, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Online Ordering System By janobe 2.3.2 is vulnerable to SQL Injection via /ordering/admin/orders/loaddata.php.
1Online Ordering System Project
1Online Ordering System
Nov 21, 2024
Jun 2, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Online Ordering System By janobe 2.3.2 has SQL Injection via /ordering/admin/products/index.php?view=edit&id=.
1Online Ordering System Project
1Online Ordering System
Nov 21, 2024
Jun 2, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Online Ordering System By janobe 2.3.2 is vulneranle to SQL Injection via /ordering/index.php?q=products&id=.
1Online Ordering System Project
1Online Ordering System
Nov 21, 2024
Jun 2, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Online Ordering System v1.0 by oretnom23 has SQL injection via store/orderpage.php.
1Online Ordering System Project
1Online Ordering System
Nov 21, 2024
Jun 2, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/viewreport.php.
1Online Ordering System Project
1Online Ordering System
Nov 21, 2024
Jun 2, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Online Ordering System 1.0 by oretnom23 is vulnerable to SQL Injection via admin/vieworders.php.
1Online Ordering System Project
1Online Ordering System
Nov 21, 2024
Jun 2, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductimage.php.
1Online Ordering System Project
1Online Ordering System
Nov 21, 2024
Jun 2, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductetails.php.
1Online Ordering System Project
1Online Ordering System
Nov 21, 2024
Jul 22, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Arbitrary file upload vulnerability in SourceCodester Ordering System v 1.0 allows attackers to execute arbitrary code, via the file upload to ordering\admin\products\edit.php.
1Online Ordering System Project
1Online Ordering System
Nov 21, 2024
Mar 16, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Online Ordering System 1.0 is vulnerable to unauthenticated SQL injection through /onlineordering/GPST/admin/design.php, which may lead to database information disclosure.