MartDevelopers
Products
3- 5 CVEs
- 2 CVEs
- 1 CVE
Recent CVEs
8| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-45802 | Cri | 0.64 | 9.8 | 0.01 | Jan 25, 2022 | MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because the email and phone parameter values are added to the SQL query without any verification at the time of membership registration. | ||
| CVE-2021-43439 | Cri | 0.64 | 9.8 | 0.03 | Dec 20, 2021 | RCE in Add Review Function in iResturant 1.0 Allows remote attacker to execute commands remotely | ||
| CVE-2021-46113 | Hig | 0.57 | 8.8 | 0.03 | Jan 25, 2022 | In MartDevelopers KEA-Hotel-ERP open source as of 12-31-2021, a remote code execution vulnerability can be exploited by uploading PHP files using the file upload vulnerability in this service. | ||
| CVE-2021-45803 | Hig | 0.57 | 8.8 | 0.01 | Jan 25, 2022 | MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because this view parameter value is added to the SQL query without additional verification when viewing reservation. | ||
| CVE-2021-43440 | Med | 0.40 | 6.1 | 0.01 | Dec 20, 2021 | Multiple Stored XSS Vulnerabilities in the Source Code of iOrder 1.0 allow remote attackers to execute arbitrary code via signup form in the Name and Phone number field. | ||
| CVE-2021-43436 | Med | 0.35 | 5.4 | 0.01 | Jan 12, 2022 | MartDevelopers Inc iResturant v1.0 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of failed logins, the XSS payload will be executed. | ||
| CVE-2021-43441 | Med | 0.35 | 5.3 | 0.01 | Dec 20, 2021 | An HTML Injection Vulnerability in iOrder 1.0 allows the remote attacker to execute Malicious HTML codes via the signup form | ||
| CVE-2021-43438 | Med | 0.35 | 5.4 | 0.01 | Dec 20, 2021 | Stored XSS in Signup Form in iResturant 1.0 Allows Remote Attacker to Inject Arbitrary code via NAME and ADDRESS field |
- risk 0.64cvss 9.8epss 0.01
MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because the email and phone parameter values are added to the SQL query without any verification at the time of membership registration.
- risk 0.64cvss 9.8epss 0.03
RCE in Add Review Function in iResturant 1.0 Allows remote attacker to execute commands remotely
- risk 0.57cvss 8.8epss 0.03
In MartDevelopers KEA-Hotel-ERP open source as of 12-31-2021, a remote code execution vulnerability can be exploited by uploading PHP files using the file upload vulnerability in this service.
- risk 0.57cvss 8.8epss 0.01
MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because this view parameter value is added to the SQL query without additional verification when viewing reservation.
- risk 0.40cvss 6.1epss 0.01
Multiple Stored XSS Vulnerabilities in the Source Code of iOrder 1.0 allow remote attackers to execute arbitrary code via signup form in the Name and Phone number field.
- risk 0.35cvss 5.4epss 0.01
MartDevelopers Inc iResturant v1.0 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of failed logins, the XSS payload will be executed.
- risk 0.35cvss 5.3epss 0.01
An HTML Injection Vulnerability in iOrder 1.0 allows the remote attacker to execute Malicious HTML codes via the signup form
- risk 0.35cvss 5.4epss 0.01
Stored XSS in Signup Form in iResturant 1.0 Allows Remote Attacker to Inject Arbitrary code via NAME and ADDRESS field