CVE-2022-36581: Online Ordering System Project Online Ordering System

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via the user_email parameter at /admin/login.php.

Affected products

Published 2022-08-31. Last modified 2026-06-17.