This CPE summary could be partial or incomplete. Please contact us for a detailed listing.
Summary
Detail | |||
---|---|---|---|
Vendor | Hockeycomputindo | First view | 2023-04-24 |
Product | Bang Resto | Last view | 2023-04-24 |
Version | 1.0 | Type | Application |
Update | * | ||
Edition | * | ||
Language | * | ||
Sofware Edition | * | ||
Target Software | * | ||
Target Hardware | * | ||
Other | * | ||
CPE Product | cpe:2.3:a:hockeycomputindo:bang_resto |
Activity : Overall
Related : CVE
Date | Alert | Description | |
---|---|---|---|
8.8 | 2023-04-24 | CVE-2023-29849 | Bang Resto 1.0 was discovered to contain multiple SQL injection vulnerabilities via the btnMenuItemID, itemID, itemPrice, menuID, staffID, or itemqty parameter. |
4.8 | 2023-04-24 | CVE-2023-29848 | Bang Resto 1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the itemName parameter in the admin/menu.php Add New Menu function. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
50% (1) | CWE-89 | Improper Sanitization of Special Elements used in an SQL Command ('... |
50% (1) | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |