VendorsiResturant Projectiresturantall versions
Vulnerabilities

iResturant Project iResturant

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2021-43439
RCE in Add Review Function in iResturant 1.0 Allows remote attacker to execute commands remotely
Published 2021-12-20 · Modified
10.0EPSS 0.034
CVE-2021-45802
MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because the email and phone parameter values are added to the SQL query without any verification at the time of membership registration.
Published 2022-01-25 · Modified
9.8EPSS 0.013
CVE-2021-45803
MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because this view parameter value is added to the SQL query without additional verification when viewing reservation.
Published 2022-01-25 · Modified
8.8EPSS 0.012
CVE-2021-43438
Stored XSS in Signup Form in iResturant 1.0 Allows Remote Attacker to Inject Arbitrary code via NAME and ADDRESS field
Published 2021-12-20 · Modified
5.4EPSS 0.007
CVE-2021-43436
MartDevelopers Inc iResturant v1.0 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of failed logins, the XSS payload will be executed.
Published 2022-01-12 · Modified
5.4EPSS 0.006