2 results (0.011 seconds)

CVSS: 5.8EPSS: 0%CPEs: 1EXPL: 0

A vulnerability, which was classified as critical, has been found in SourceCodester Online Food Menu 1.0. This issue affects some unknown processing of the file /endpoint/delete-menu.php. The manipulation of the argument menu leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. • https://vuldb.com/?ctiid.276779 https://vuldb.com/?id.276779 https://vuldb.com/?submit.403497 https://www.sourcecodester.com • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 4.8EPSS: 0%CPEs: 1EXPL: 2

Sourcecodester Online Food Menu 1.0 is vulnerable to Cross Site Scripting (XSS) via the 'Menu Name' and 'Description' fields in the Update Menu section. Sourcecodester Online Food Menu 1.0 es vulnerable a Cross Site Scripting (XSS) a través de los campos 'Menu Name' y 'Description' en la sección Update Menu. • https://github.com/BurakSevben/CVE-2024-24134 https://github.com/BurakSevben/2024_Online_Food_Menu_XSS • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •