Description
A vulnerability was identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. The affected element is the function mysqli_query of the file User/cancel.php of the component Order Cancellation. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-30
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: SQL Injection
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the mysqli_query call inside User/cancel.php of the Order Cancellation component. Because the argument ID is not validated or sanitized, an attacker can supply arbitrary SQL code. The result is a classic SQL injection that can read, modify, or delete data in the database. The attack vector is remote, as the vulnerable script is exposed via the web interface. The presence of publicly available exploits indicates that an attacker can easily craft requests.

Affected Systems

The affected product is the AdithyaYelloju Restaurant-Management-System, as distributed up to the commit 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Software versions prior to that commit contain the vulnerable code. The vulnerability affects all installations that use the Order Cancellation feature. No additional versions are listed.

Risk and Exploitability

The CVSS base score of 6.9 reflects a moderate severity with potential impact on confidentiality, integrity, and availability. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, however publicly available exploits make it likely to be abused. Remote attackers can exploit the flaw by sending crafted requests to cancel.php. The absence of input sanitization and the use of raw query strings increase the exploitability. Because no patch is currently released, the risk remains significantly high for exposed servers.

Generated by OpenCVE AI on September 30, 2026 at 17:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Restaurant-Management-System to the latest commit that addresses the SQL injection or replace the User/cancel.php implementation with parameterized queries using prepared statements.
  • Apply server‑side input validation on the ID parameter to ensure it contains only numeric identifiers before constructing the SQL statement.
  • Restrict access to the cancel.php endpoint to authenticated users and enforce least‑privilege database permissions so that even if injection occurs, damage is limited.
  • Monitor application logs for suspicious SQL patterns and consider deploying a web application firewall tuned to detect SQL injection attempts.

Generated by OpenCVE AI on September 30, 2026 at 17:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. The affected element is the function mysqli_query of the file User/cancel.php of the component Order Cancellation. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Title AdithyaYelloju Restaurant-Management-System Order Cancellation cancel.php mysqli_query sql injection
First Time appeared Adithyayelloju
Adithyayelloju restaurant-management-system
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:adithyayelloju:restaurant-management-system:*:*:*:*:*:*:*:*
Vendors & Products Adithyayelloju
Adithyayelloju restaurant-management-system
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Adithyayelloju Restaurant-management-system
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-30T16:00:11.743Z

Reserved: 2026-09-30T08:09:16.943Z

Link: CVE-2026-103231

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-30T16:17:08.657

Modified: 2026-09-30T16:38:36.297

Link: CVE-2026-103231

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T17:30:19Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')