← Back to overview

A SQL injection vulnerability has been identified in SourceCodester Simple Online Food Ordering System version 1.0. The vulnerability exists in the file /fos/admin/ajax.php?action=confirm_order, where manipulation of the 'ID' argument leads to SQL injection. The attack can be executed remotely without requiring physical access to the target system. A public exploit has been released, increasing the risk of active exploitation. The vulnerability affects the admin panel's order confirmation functionality. It has been catalogued under CVE-2026-78247 and is listed on multiple vulnerability tracking platforms including NVD and VulDB. Organizations using this software should apply patches or mitigations immediately. The public disclosure of the exploit raises the criticality of this issue significantly.

Affected products

  • SourceCodester Simple Online Food Ordering System 1.0

Related CVE's

  • CVE-2026-78247

Categories

  • Database & Storage
  • Web Technologies