Karenderia Multiple Restaurant System 5.3 SQL注入误差清静通告

宣布时间 2019-07-10

误差编号和级别


CVE编号:暂无,危险级别:高危,CVSS分值:官方未评定


影响版本


受影响的版本


适用于Karenderia Multiple Restaurant System 5.3。


误差概述


Karenderia CMS是一个餐厅点餐和餐厅会员制度。Karenderia Multiple Restaurant System 5.3版本保存SQL注入误差。该误差源于未对用户输入的数据举行严酷过滤,Karenderia Multiple Restaurant System 5.3版本street-name、category参数保存SQL注入。


误差验证


误差POC:https://cxsecurity.com/issue/WLB-2019070037。


修复建议


现在厂商暂未宣布修复步伐解决此清静问题,建议使用此软件的用户随时关注厂商主页或参考网址以获取解决步伐:
https://codecanyon.net/item/karenderia-multiple-restaurant-system/9118694。