MartDevelopers-Inc/iResturant

MartDevelopers-Inc/iResturant

Releases0
Stars4
iResturant - A Lightweight Resturant ERP

CVE History

CVEPublishedCVSS v3CVSS v2
5.4 MEDIUM3.5 LOW

MartDevelopers Inc iResturant v1.0 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of failed logins, the XSS payload will be executed.

5.4 MEDIUM3.5 LOW

Stored XSS in Signup Form in iResturant 1.0 Allows Remote Attacker to Inject Arbitrary code via NAME and ADDRESS field

9.8 CRITICAL10 HIGH

RCE in Add Review Function in iResturant 1.0 Allows remote attacker to execute commands remotely