CVE-2022-31338: Online Ordering System Project Online Ordering System

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/user/index.php?view=edit&id=.

Affected products

Published 2022-06-02. Last modified 2026-06-17.