← Back to overview

A SQL injection vulnerability has been identified in SililaWijesinghe's Food Ordering System, affecting the /search.php file. The vulnerability is triggered by manipulating the 'search_box' argument, allowing remote attackers to perform SQL injection attacks. The affected version spans up to commit ba314e897e3365600461e5ea59432e39ceaa0fa5. The product uses a rolling release model, making specific version identification difficult. The exploit has been publicly disclosed and is available for use. Remote exploitation is possible, increasing the risk of unauthorized database access or data exfiltration. The vendor was notified prior to public disclosure but did not respond. No patch or mitigation has been officially confirmed. The public availability of the exploit elevates the urgency for users of this system to take protective measures.

Affected products

  • SililaWijesinghe Food Ordering System

Related CVE's

  • CVE-2026-79804

Categories

  • Database & Storage
  • Web Technologies