VYPR
Vendor

Iresturant Project

Products
1
CVEs
5
Across products
5
Status
Private

Products

1

Recent CVEs

5
  • CVE-2021-45802CriJan 25, 2022
    risk 0.64cvss 9.8epss 0.01

    MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because the email and phone parameter values are added to the SQL query without any verification at the time of membership registration.

  • CVE-2021-43439CriDec 20, 2021
    risk 0.64cvss 9.8epss 0.03

    RCE in Add Review Function in iResturant 1.0 Allows remote attacker to execute commands remotely

  • CVE-2021-45803HigJan 25, 2022
    risk 0.57cvss 8.8epss 0.01

    MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because this view parameter value is added to the SQL query without additional verification when viewing reservation.

  • CVE-2021-43436MedJan 12, 2022
    risk 0.35cvss 5.4epss 0.01

    MartDevelopers Inc iResturant v1.0 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of failed logins, the XSS payload will be executed.

  • CVE-2021-43438MedDec 20, 2021
    risk 0.35cvss 5.4epss 0.01

    Stored XSS in Signup Form in iResturant 1.0 Allows Remote Attacker to Inject Arbitrary code via NAME and ADDRESS field