在 SourceCodester Simple Online Food Ordering System 1.0 中发现了一个漏洞。该问题影响文件 /fos/admin/ajax.php?action=confirm_order 中某些未知的处理逻辑。通过操控参数 ID,可导致 SQL 注入。该漏洞可被远程利用,相关利用代码已公开,可能被恶意利用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | Simple Online Food Ordering System | 1.0 |
cpe:2.3:a:sourcecodester:simple_online_food_ordering_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-78248 | 7.3 HIGH | SourceCodester Simple Online Food Ordering System ajax.php save_settings sql injection |
| CVE-2026-78199 | 7.3 HIGH | SourceCodester Simple Online Food Ordering System view_prod.php sql injection |
| CVE-2026-78198 | 7.3 HIGH | SourceCodester Simple Online Food Ordering System ajax.php add_to_cart sql injection |
| CVE-2026-78197 | 7.3 HIGH | SourceCodester Simple Online Food Ordering System ajax.php save_user sql injection |
No comments yet