← Terug naar overzicht

A SQL injection vulnerability was identified in SourceCodester Simple Online Food Ordering System version 1.0. The flaw exists in the file /fos/admin/ajax.php?action=save_settings, where manipulation of the 'Name' argument leads to SQL injection. The vulnerability can be exploited remotely without requiring physical access. A public exploit has been disclosed and is available for use by threat actors. The affected product is a PHP-based web application commonly used for learning and small-scale deployments. The vulnerability poses a significant risk as it could allow attackers to manipulate or extract database contents. No patch details are currently mentioned in the article. The issue has been documented across multiple security databases including NVD and VulDB.

Affected products

  • SourceCodester Simple Online Food Ordering System 1.0

Related CVE's

  • CVE-2026-78248

Categories

  • Database & Storage
  • Web Technologies
  • Zero-Day Vulnerabilities