CVE-2024-1268 – CodeAstro Restaurant POS System update_product.php unrestricted upload
https://notcve.org/view.php?id=CVE-2024-1268
A vulnerability, which was classified as critical, was found in CodeAstro Restaurant POS System 1.0. This affects an unknown part of the file update_product.php. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. • https://drive.google.com/drive/folders/1utXNnlH67FjUaBsYhw1cQWyZsO9MLy1i?usp=sharing https://vuldb.com/?ctiid.253011 https://vuldb.com/?id.253011 • CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2024-1267 – CodeAstro Restaurant POS System create_account.php cross site scripting
https://notcve.org/view.php?id=CVE-2024-1267
A vulnerability, which was classified as problematic, has been found in CodeAstro Restaurant POS System 1.0. Affected by this issue is some unknown functionality of the file create_account.php. The manipulation of the argument Full Name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. • https://drive.google.com/drive/folders/18N_20KuGPjrBbvOMSfbvBIc1sMKyycH3?usp=sharing https://vuldb.com/?ctiid.253010 https://vuldb.com/?id.253010 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-43085
https://notcve.org/view.php?id=CVE-2022-43085
An arbitrary file upload vulnerability in add_product.php of Restaurant POS System v1.0 allows attackers to execute arbitrary code via a crafted PHP file. Una vulnerabilidad de carga de archivos arbitrarios en add_product.php de Restaurant POS System v1.0 permite a atacantes ejecutar código arbitrario a través de un archivo PHP manipulado. • https://github.com/Tr0e/CVE_Hunter/blob/main/RCE-3.md • CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2022-43086
https://notcve.org/view.php?id=CVE-2022-43086
Restaurant POS System v1.0 was discovered to contain a SQL injection vulnerability via update_customer.php. Se descubrió que Restaurant POS System v1.0 contenía una vulnerabilidad de inyección SQL a través de update_customer.php. • https://github.com/Tr0e/CVE_Hunter/blob/main/SQLi-4.md • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •