A SQL injection vulnerability has been identified in SourceCodester Simple Online Food Ordering System version 1.0. The flaw exists in the file /fos/admin/ajax.php?action=save_user, where manipulation of the Username argument allows SQL injection attacks. The vulnerability can be exploited remotely without requiring local access. A public exploit has already been released, increasing the risk of active exploitation. The issue affects an unknown code segment within the admin panel. Attackers could potentially leverage this to access, modify, or delete database contents. The vulnerability has been documented on NVD, VulDB, and GitHub.