vendor:
Yoga Class Registration System
by:
Abdulhakim Öner
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Yoga Class Registration System
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE: a:sourcecodester:yoga_class_registration_system
Platforms Tested: Windows, Linux
2023
Yoga Class Registration System v1.0 – Multiple SQLi
A Blind SQL injection vulnerability in the 'cid' parameter in Online Pizza Ordering System allows remote unauthenticated attackers to dump database through arbitrary SQL commands.
Mitigation:
Input validation and sanitization should be used to prevent SQL injection attacks.