Business Logic Errors in SourceCodester Online Food Ordering System by SourceCodester
CVE-2026-5811
Key Information:
- Vendor
Sourcecodester
- Vendor
- CVE Published:
- 8 April 2026
Badges
What is CVE-2026-5811?
A vulnerability exists in the SourceCodester Online Food Ordering System's POST Parameter Handler within the save_product function. An attacker can manipulate the price argument in the /Actions.php file, potentially leading to critical business logic errors. This flaw allows for exploitation from a remote location, and public exploits are available, heightening the risk for users of this system. It is crucial for administrators to review their configurations and implement fixes to mitigate potential misuse.
Affected Version(s)
Online Food Ordering System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
