← Terug naar overzicht

A SQL injection vulnerability has been identified in SourceCodester Simple Online Food Ordering System version 1.0. The vulnerability exists in the file /fos/admin/ajax.php?action=save_settings, where manipulation of the 'Name' argument leads to SQL injection. The flaw can be exploited remotely without requiring physical access to the target system. A public exploit has already been disclosed, increasing the risk of active exploitation. The vulnerability affects an unknown function within the identified file endpoint. Given the public availability of the exploit, organizations using this software are at heightened risk. No patch or mitigation details are currently noted in the article. The vulnerability has been catalogued on NVD, VulDB, and referenced via a GitHub issue. SourceCodester is a known provider of free source code projects often used in educational or small-scale deployments. Immediate review and remediation are advised for any deployments of this system.

Affected products

  • SourceCodester Simple Online Food Ordering System 1.0

Related CVE's

  • CVE-2026-78248

Categories

  • Database & Storage
  • Web Technologies