← Terug naar overzicht

A SQL injection vulnerability has been identified in SourceCodester Simple Online Food Ordering System version 1.0. The vulnerability exists in the file /fos/view_prod.php, where manipulation of the 'ID' argument allows SQL injection attacks. The vulnerability can be exploited remotely without requiring local access. A public exploit is already available, increasing the risk of active exploitation. The affected function within the file is currently unspecified. The vulnerability has been catalogued under CVE-2026-78199 and is tracked on NVD, VulDB, and GitHub. Organizations using this software should apply patches or mitigations immediately given the public exploit availability.

Affected products

  • SourceCodester Simple Online Food Ordering System 1.0

Related CVE's

  • CVE-2026-78199

Categories

  • Database & Storage
  • Web Technologies
  • Zero-Day Vulnerabilities