SQL Injection Vulnerability in SourceCodester Online Food Ordering System
CVE-2026-90854
6.9MEDIUM
What is CVE-2026-90854?
A security flaw in the SourceCodester/katojkalemba Online Food Ordering System version 1.0 has been identified, specifically in the file /web/category-foods.php. The vulnerability arises from an unprotected function that allows manipulation of the argument ID, resulting in SQL injection possibilities. This vulnerability can be exploited remotely, exposing the system to potential attacks. As the exploit has been publicly disclosed, immediate action should be taken to mitigate risks associated with this weakness.
Affected Version(s)
Online Food Ordering System 1.0
Online Food Ordering System 1.0
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
ameenk (VulDB User)
VulDB Vulnerability Moderation Team
