← Terug naar overzicht

A SQL injection vulnerability has been identified in SourceCodester Simple Online Food Ordering System version 1.0. The flaw exists in the file /fos/admin/view_order.php, where manipulation of the 'ID' argument leads to SQL injection. The vulnerability can be exploited remotely without requiring physical access to the target system. A public exploit has already been released, increasing the risk of active exploitation. The affected component involves an unknown function within the admin panel of the application. This vulnerability poses a significant risk to systems running this software, as attackers could potentially access, modify, or delete database contents. The public availability of the exploit makes prompt patching or mitigation critical for affected deployments.

Affected products

  • SourceCodester Simple Online Food Ordering System 1.0

Related CVE's

  • CVE-2026-76996

Categories

  • Database & Storage
  • Web Technologies