Vulnerabilities
5 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-45802 +1 in the same advisory: …45803 | MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because the email and phone parameter values are added to the SQL query without any verification at the time of membership registration. NVD description · AI analysis pending | 9.8 group max | 1% | PoC |
| — | |
| CVE-2021-43436 | MartDevelopers Inc iResturant v1.0 allows Stored XSS by placing a payload in the username field during a login attempt. MartDevelopers Inc iResturant v1.0 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of failed logins, the XSS payload will be executed. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2021-43439 +1 in the same advisory: …43438 | RCE in Add Review Function in iResturant 1.0 Allows remote attacker to execute commands remotely RCE in Add Review Function in iResturant 1.0 Allows remote attacker to execute commands remotely NVD description · AI analysis pending | 9.8 group max | 3% |
| — |