← Terug naar overzicht

A SQL injection vulnerability has been identified in SourceCodester Simple Online Food Ordering System version 1.0. The vulnerability exists in the file /fos/admin/ajax.php?action=add_to_cart, where manipulation of the 'pid' argument leads to SQL injection. The attack can be launched remotely without physical access to the target system. The exploit has been publicly disclosed and is available for use by threat actors. This represents a significant risk as it allows remote attackers to potentially access, modify, or delete database contents. The vulnerability affects an unknown portion of the application's processing logic. No patch or mitigation details are currently mentioned in the advisory.

Affected products

  • SourceCodester Simple Online Food Ordering System 1.0

Related CVE's

  • CVE-2026-78198

Categories

  • Database & Storage
  • Web Technologies