Record summary

CVE-2023-40749 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

PHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the "column" parameter of index.php.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 2, 2024 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryCRITICALPHPJabbers Food Delivery Script v3.0 - SQL InjectionCVSS 9.8

PHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the "column" parameter of index.php.

Impact

Unauthenticated attackers can exploit SQL injection in the column parameter to extract sensitive database information including customer orders, payment details, delivery addresses, and admin credentials from the Food Delivery platform.

Remediation

Update PHPJabbers Food Delivery Script to a version newer than 3.0 that properly sanitizes the column parameter and uses parameterized queries.

WeaknessesCWE-89
Authorsritikchaddha
Template tagscvecve2023phpjabbersfood-deliverysqlivuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:phpjabbers:food_delivery_script:3.0:*:*:*:*:*:*:*
Shodan: html:"PHPJabbers"

Source: ProjectDiscovery

References

4