A SQL injection vulnerability has been identified in SourceCodester Simple Online Food Ordering System version 1.0. The flaw exists in the file /fos/admin/ajax.php?action=save_user, where manipulation of the Username argument allows SQL injection attacks. The vulnerability can be exploited remotely without requiring physical access to the target system. A public exploit has already been released, increasing the risk of active exploitation. The vulnerability has been assigned CVE-2026-78197 and is tracked in VulDB as vuln/394574. No patch or mitigation details are currently mentioned in the article. The public availability of the exploit makes this a higher-risk issue for any organization running this software.