ZeroHour

Vulnerabilities

5 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-45802
+1 in the same advisory: …45803
MartDevelopers iResturant 1.0 is vulnerable to SQL Injection.

MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because the email and phone parameter values are added to the SQL query without any verification at the time of membership registration.

NVD description · AI analysis pending
9.8
group max
1% PoC
  • iresturant project iresturant
CVE-2021-43436
MartDevelopers Inc iResturant v1.0 allows Stored XSS by placing a payload in the username field during a login attempt.

MartDevelopers Inc iResturant v1.0 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of failed logins, the XSS payload will be executed.

NVD description · AI analysis pending
5.4<1%
  • iresturant project iresturant
CVE-2021-43439
+1 in the same advisory: …43438
RCE in Add Review Function in iResturant 1.0 Allows remote attacker to execute commands remotely

RCE in Add Review Function in iResturant 1.0 Allows remote attacker to execute commands remotely

NVD description · AI analysis pending
9.8
group max
3%
  • iresturant project iresturant