Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, which may lead to remote code execution (RCE).
| Software | From | Fixed in |
|---|---|---|
| online_ordering_system_project / online_ordering_system | 1.0 | 1.0.x |