← Terug naar overzicht

A SQL injection vulnerability has been identified in SourceCodester Simple Online Food Ordering System version 1.0. The vulnerability exists in the file /fos/view_prod.php, where manipulation of the 'ID' argument allows an attacker to perform SQL injection. The vulnerability can be exploited remotely without requiring local access. A public exploit is already available, increasing the risk of active exploitation. The affected product is a web-based food ordering application. No authentication bypass details are specified, but the remote attack vector makes it broadly accessible to threat actors. The vulnerability has been catalogued in VulDB and NVD. Users of the affected system are advised to apply patches or mitigations immediately.

Affected products

  • SourceCodester Simple Online Food Ordering System 1.0

Related CVE's

  • CVE-2026-78199

Categories

  • Database & Storage
  • Web Technologies