HOMEVULNERABILITIESVENDORSFast Food Ordering System Project

Fast Food Ordering System ProjectCVEs & Vulnerabilities

15 CVEs affecting Fast Food Ordering System Project products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

fast food ordering system 15
CVE-2022-43082MEDIUM

A cross-site scripting (XSS) vulnerability in /fastfood/purchase.php of Fast Food Ordering System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the customer parameter.

1 Nov 2022
6.1
CVSS
CVE-2022-43081HIGH

Fast Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the component /fastfood/purchase.php.

1 Nov 2022
7.5
CVSS
CVE-2022-3015MEDIUM

A vulnerability, which was classified as problematic, has been found in oretnom23 Fast Food Ordering System. This issue affects some unknown processing of the file admin/?page=reports. The manipulation of the argument date leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-207425 was assigned to this vulnerability.

27 Aug 2022
6.1
CVSS
CVE-2022-3012HIGH

A vulnerability was found in oretnom23 Fast Food Ordering System. It has been rated as critical. Affected by this issue is some unknown functionality of the file ffos/admin/reports/index.php. The manipulation of the argument date leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-207422 is the identifier assigned to this vulnerability.

27 Aug 2022
8.8
CVSS
CVE-2022-2686MEDIUM

A vulnerability, which was classified as problematic, was found in oretnom23 Fast Food Ordering System. This affects an unknown part of the component Menu List Page. The manipulation of the argument Description leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-205725 was assigned to this vulnerability.

6 Aug 2022
5.4
CVSS
CVE-2022-32318MEDIUM

Fast Food Ordering System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via the component /ffos/classes/Master.php?f=save_category.

14 Jul 2022
5.4
CVSS
CVE-2022-32335HIGH

Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/menus/manage_menu.php?id=.

14 Jun 2022
7.2
CVSS
CVE-2022-32334HIGH

Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/categories/manage_category.php?id=.

14 Jun 2022
7.2
CVSS
CVE-2022-32333HIGH

Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/sales/receipt.php?id=.

14 Jun 2022
7.2
CVSS
CVE-2022-32332HIGH

Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/classes/Master.php?f=delete_category.

14 Jun 2022
7.2
CVSS
CVE-2022-32331HIGH

Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/categories/view_category.php?id=.

14 Jun 2022
7.2
CVSS
CVE-2022-32330HIGH

Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/classes/Master.php?f=delete_menu.

14 Jun 2022
7.2
CVSS
CVE-2022-32328CRITICAL

Fast Food Ordering System v1.0 is vulnerable to Delete any file. via /ffos/classes/Master.php?f=delete_img.

14 Jun 2022
9.1
CVSS
CVE-2022-32336CRITICAL

Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/menus/view_menu.php?id=.

14 Jun 2022
9.8
CVSS
CVE-2022-1991MEDIUM

A vulnerability classified as problematic has been found in Fast Food Ordering System 1.0. Affected is the file Master.php of the Master List. The manipulation of the argument Description with the input foo "><img src="" onerror="alert(document.cookie)"> leads to cross site scripting. It is possible to launch the attack remotely but it requires authentication. Exploit details have been disclosed to the public.

7 Jun 2022
4.8
CVSS
← PrevPage 1 / 1Next →