Impact
The vulnerability resides in the mysqli_query call inside User/cancel.php of the Order Cancellation component. Because the argument ID is not validated or sanitized, an attacker can supply arbitrary SQL code. The result is a classic SQL injection that can read, modify, or delete data in the database. The attack vector is remote, as the vulnerable script is exposed via the web interface. The presence of publicly available exploits indicates that an attacker can easily craft requests.
Affected Systems
The affected product is the AdithyaYelloju Restaurant-Management-System, as distributed up to the commit 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Software versions prior to that commit contain the vulnerable code. The vulnerability affects all installations that use the Order Cancellation feature. No additional versions are listed.
Risk and Exploitability
The CVSS base score of 6.9 reflects a moderate severity with potential impact on confidentiality, integrity, and availability. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, however publicly available exploits make it likely to be abused. Remote attackers can exploit the flaw by sending crafted requests to cancel.php. The absence of input sanitization and the use of raw query strings increase the exploitability. Because no patch is currently released, the risk remains significantly high for exposed servers.
OpenCVE Enrichment