在 SourceCodester Simple Online Food Ordering System 1.0 中发现了一个漏洞。该问题影响对文件 /admin/ajax.php?action=save_menu 的某些未知处理过程。通过操纵参数 img,可实现不受限制的文件上传。该攻击可远程执行。目前相关利用代码已公开,可能被恶意利用。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SourceCodester | Simple Online Food Ordering System | 1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | Simple Online Food Ordering System | 1.0 |
cpe:2.3:a:sourcecodester:simple_online_food_ordering_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-76998 | 7.3 HIGH | SourceCodester Simple Online Food Ordering System ajax.php delete_category sql injection |
| CVE-2026-76996 | 7.3 HIGH | SourceCodester Simple Online Food Ordering System view_order.php sql injection |
| CVE-2026-76999 | 6.3 MEDIUM | SourceCodester CET Automated Grading System with AI Predictive Analytics index.php add_gra |
| CVE-2026-76997 | 6.3 MEDIUM | SourceCodester Simple Online Food Ordering System ajax.php save_category sql injection |
No comments yet