Show filters
104 Total Results
Displaying 71-80 of 104
Sort by:
Attacker Value
Unknown

CVE-2022-0421

Disclosure Date: November 21, 2022 (last updated November 08, 2023)
The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a payment was successful or failed, allowing unauthenticated users to change the payment status of arbitrary bookings. Furthermore, due to the lack of sanitisation and escaping, attackers could perform Cross-Site Scripting attacks against a logged in admin viewing the failed payments
Attacker Value
Unknown

CVE-2022-3776

Disclosure Date: November 03, 2022 (last updated November 08, 2023)
The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.1. This is due to missing or incorrect nonce validation on several functions called via AJAX actions such as forms_action, set_option, & chosen_options to name a few . This makes it possible for unauthenticated attackers to perform a variety of administrative actions like modifying forms, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2022-2696

Disclosure Date: November 03, 2022 (last updated November 08, 2023)
The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to authorization bypass via several AJAX actions in versions up to, and including 2.3.0 due to missing capability checks and missing nonce validation. This makes it possible for authenticated attackers with minimal permissions to perform a wide variety of actions such as modifying the plugin's settings and modifying the ordering system preferences.
Attacker Value
Unknown

CVE-2022-43085

Disclosure Date: November 01, 2022 (last updated February 15, 2024)
An arbitrary file upload vulnerability in add_product.php of Restaurant POS System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
Attacker Value
Unknown

CVE-2022-43086

Disclosure Date: November 01, 2022 (last updated February 15, 2024)
Restaurant POS System v1.0 was discovered to contain a SQL injection vulnerability via update_customer.php.
Attacker Value
Unknown

CVE-2022-2754

Disclosure Date: September 19, 2022 (last updated October 08, 2023)
The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not validate and escape some reservation parameters before using them in SQL statements, which could allow unauthenticated attackers to perform SQL Injection attacks
Attacker Value
Unknown

CVE-2022-2753

Disclosure Date: September 19, 2022 (last updated October 08, 2023)
The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not sanitise and escape some of the reservation user inputs, allowing unauthenticated attackers to perform Cross-Site Scripting attacks logged in admin viewing the malicious reservation made
Attacker Value
Unknown

CVE-2020-36553

Disclosure Date: July 15, 2022 (last updated October 07, 2023)
Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Area(food_type) field to /dashboard/menu-list.php.
Attacker Value
Unknown

CVE-2020-36552

Disclosure Date: July 15, 2022 (last updated October 07, 2023)
Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Made field to /dashboard/menu-list.php.
Attacker Value
Unknown

CVE-2020-36551

Disclosure Date: July 15, 2022 (last updated October 07, 2023)
Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Item Name field to /dashboard/menu-list.php.