在 SourceCodester Simple Online Food Ordering System 1.0 中发现了一个弱点。该漏洞影响文件 /fos/admin/ajax.php?action=save_user 中的未知代码。对用户名字参数的操纵可导致 SQL 注入。攻击可能从远程发起。该漏洞利用代码已公开,可能被用于实施攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | Simple Online Food Ordering System | 1.0 |
cpe:2.3:a:sourcecodester:simple_online_food_ordering_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-78199 | 7.3 HIGH | SourceCodester Simple Online Food Ordering System view_prod.php sql injection |
| CVE-2026-78198 | 7.3 HIGH | SourceCodester Simple Online Food Ordering System ajax.php add_to_cart sql injection |
No comments yet