CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.8. It involves a SQL injection risk. Exploitation may require the attacker to be authenticated.
CVE
CVE-2026-24494
Severity
CRITICAL
CVSS
9.8
EPSS
0.36%
Original NVD Description
SQL Injection vulnerability in the /api/integrations/getintegrations endpoint of Order Up Online Ordering System 1.0 allows an unauthenticated attacker to access sensitive backend database data via a crafted store_id parameter in a POST request.