CVE-2023-29849

HIGH

Hockeycomputindo Bang Resto - SQL Injection

Title source: rule

Description

Bang Resto 1.0 was discovered to contain multiple SQL injection vulnerabilities via the btnMenuItemID, itemID, itemPrice, menuID, staffID, or itemqty parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Rahad Chowdhury · textwebappsphp
https://www.exploit-db.com/exploits/51378

Scores

CVSS v3 8.8
EPSS 0.0141
EPSS Percentile 80.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
hockeycomputindo/bang_resto 1.0
Published Apr 24, 2023
Tracked Since Feb 18, 2026