SQL Injection vulnerability in the /api/integrations/getintegrations endpoint of Order Up Online Ordering System 1.0 allows an unauthenticated attacker to access sensitive backend database data via a crafted store_id parameter in a POST request.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 23 Feb 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL Injection vulnerability in the /api/integrations/getintegrations endpoint of Order Up Online Ordering System 1.0 allows an unauthenticated attacker to access sensitive backend database data via a crafted store_id parameter in a POST request. | |
| Title | SQL injection vulnerability in Order Up Online Ordering System | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: spartans-security
Published:
Updated: 2026-02-23T01:24:48.333Z
Reserved: 2026-01-23T01:44:12.352Z
Link: CVE-2026-24494
No data.
Status : Received
Published: 2026-02-23T02:16:39.443
Modified: 2026-02-23T02:16:39.443
Link: CVE-2026-24494
No data.
OpenCVE Enrichment
No data.
Weaknesses