在 AdithyaYelloju Restaurant-Management-System 项目(版本至 commit 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c)中检测到一处安全漏洞。该漏洞影响 Admin Area 组件中 /admin/ 文件的一个未知函数。通过操纵 ID 参数,攻击者可绕过授权机制。该漏洞可被远程利用。相关利用方法已公开披露,可能被实际使用。项目方此前已通过问题报告获知此漏洞,但至今未作出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AdithyaYelloju | Restaurant-Management-System | 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c |
cpe:2.3:a:adithyayelloju:restaurant-management-system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103230 | 7.3 HIGH | AdithyaYelloju Restaurant-Management-System Order Placement ord.php mysqli_query sql injec |
| CVE-2026-103231 | 7.3 HIGH | AdithyaYelloju Restaurant-Management-System Order Cancellation cancel.php mysqli_query sql |
| CVE-2026-103229 | 7.3 HIGH | AdithyaYelloju Restaurant-Management-System Unauthenticated Action Script delete1.php mysq |
| CVE-2026-103232 | 7.3 HIGH | AdithyaYelloju Restaurant-Management-System table_booking.php mysqli_query sql injection |
No comments yet