CVE-2023-45345 is a critical unauthenticated SQL Injection vulnerability affecting Online Food Ordering System v1.0, specifically within the 'projectworlds online_food_ordering_script'. This flaw allows attackers to inject malicious SQL commands via the '_deleted' parameter in routers/user-router.php due to a lack of input validation. With a CVSS score of 9.8, it poses a severe risk of complete compromise of confidentiality, integrity, and availability, requiring no authentication or user interaction. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:projectworlds:online_food_ordering_script:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.