← Terug naar overzicht

A SQL injection vulnerability has been identified in SourceCodester Simple Online Food Ordering System version 1.0. The vulnerability exists in the file /fos/admin/ajax.php?action=confirm_order, where manipulation of the 'ID' argument leads to SQL injection. The attack can be executed remotely without requiring physical access. A public exploit has been released, increasing the risk of active exploitation. The vulnerability affects the admin panel's order confirmation functionality. No authentication bypass details are specified, but the remote exploitability and public exploit availability make this a significant threat. Organizations using this software should apply patches or mitigations immediately.

Affected products

  • SourceCodester Simple Online Food Ordering System 1.0

Related CVE's

  • CVE-2026-78247

Categories

  • Database & Storage
  • Web Technologies