VYPR

Ketchup Restaurant Reservations

by Ketchup Restaurant Reservations Project

CVEs (2)

  • CVE-2022-2754CriSep 19, 2022
    risk 0.67cvss 9.8epss 0.38

    The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not validate and escape some reservation parameters before using them in SQL statements, which could allow unauthenticated attackers to perform SQL Injection attacks

  • CVE-2022-2753MedSep 19, 2022
    risk 0.46cvss 6.1epss 0.83

    The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not sanitise and escape some of the reservation user inputs, allowing unauthenticated attackers to perform Cross-Site Scripting attacks logged in admin viewing the malicious reservation made