在 SourceCodester Simple Online Food Ordering System 1.0 中发现了一个安全漏洞。该问题影响对文件 /fos/admin/ajax.php?action=add_to_cart 中某些未知的处理逻辑。通过操纵参数 pid,可导致 SQL 注入。该攻击可由远程发起。该漏洞的利用方式已公开披露,可能被攻击者利用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | Simple Online Food Ordering System | 1.0 |
cpe:2.3:a:sourcecodester:simple_online_food_ordering_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-78248 | 7.3 HIGH | SourceCodester Simple Online Food Ordering System ajax.php save_settings sql injection |
| CVE-2026-78247 | 7.3 HIGH | SourceCodester Simple Online Food Ordering System ajax.php confirm_order sql injection |
| CVE-2026-78199 | 7.3 HIGH | SourceCodester Simple Online Food Ordering System view_prod.php sql injection |
| CVE-2026-78197 | 7.3 HIGH | SourceCodester Simple Online Food Ordering System ajax.php save_user sql injection |
No comments yet