← Back to overview

A SQL injection vulnerability has been identified in SourceCodester Simple Online Food Ordering System version 1.0. The vulnerability exists in the file /fos/admin/ajax.php?action=add_to_cart, where manipulation of the 'pid' argument allows SQL injection attacks. The attack can be launched remotely without requiring physical access to the target system. A public exploit has been disclosed, increasing the risk of active exploitation. The vulnerability has been assigned CVE-2026-78198 and is documented in the NVD database. This type of vulnerability can allow attackers to read, modify, or delete database contents. It poses a significant risk to any organization running the affected software version. The issue was submitted and tracked via VulDB in addition to the NVD. No patch or mitigation details are mentioned in the article.

Affected products

  • SourceCodester Simple Online Food Ordering System 1.0

Related CVE's

  • CVE-2026-78198

Categories

  • Database & Storage
  • Web Technologies