Restaurant Pos System
by Codeastro
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-43085 | Hig | 0.47 | 7.2 | 0.01 | Nov 1, 2022 | An arbitrary file upload vulnerability in add_product.php of Restaurant POS System v1.0 allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2024-1268 | Med | 0.41 | 6.3 | 0.01 | Feb 7, 2024 | A vulnerability, which was classified as critical, was found in CodeAstro Restaurant POS System 1.0. This affects an unknown part of the file update_product.php. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been… | ||
| CVE-2022-43086 | Med | 0.32 | 4.9 | 0.01 | Nov 1, 2022 | Restaurant POS System v1.0 was discovered to contain a SQL injection vulnerability via update_customer.php. | ||
| CVE-2024-1267 | Low | 0.23 | 3.5 | 0.00 | Feb 7, 2024 | A vulnerability, which was classified as problematic, has been found in CodeAstro Restaurant POS System 1.0. Affected by this issue is some unknown functionality of the file create_account.php. The manipulation of the argument Full Name leads to cross site scripting. The attack… |
- risk 0.47cvss 7.2epss 0.01
An arbitrary file upload vulnerability in add_product.php of Restaurant POS System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.41cvss 6.3epss 0.01
A vulnerability, which was classified as critical, was found in CodeAstro Restaurant POS System 1.0. This affects an unknown part of the file update_product.php. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been…
- risk 0.32cvss 4.9epss 0.01
Restaurant POS System v1.0 was discovered to contain a SQL injection vulnerability via update_customer.php.
- risk 0.23cvss 3.5epss 0.00
A vulnerability, which was classified as problematic, has been found in CodeAstro Restaurant POS System 1.0. Affected by this issue is some unknown functionality of the file create_account.php. The manipulation of the argument Full Name leads to cross site scripting. The attack…