Description
A security vulnerability has been detected in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This impacts an unknown function of the file /admin/ of the component Admin Area. Such manipulation of the argument ID leads to authorization bypass. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-30
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Authorization Bypass
Action: Assess Impact
AI Analysis

Impact

The vulnerability resides in the AdithyaYelloju Restaurant‑Management‑System, specifically in the unprotected admin interface at /admin/. An attacker can manipulate the ID argument to bypass authorization controls, gaining unauthorized access to privileged administrative functions. This flaw maps to authorization bypass (CWE‑285) and privilege escalation via control bypass (CWE‑639).

Affected Systems

The affected product is the Restaurant‑Management‑System by AdithyaYelloju. The flaw exists in code versions up to commit 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. No official patch is available yet, so any installation using the impacted code base is vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate risk. The EPSS score is not available, so the exploitation probability cannot be quantified, but a publicly disclosed exploit exists. The issue is not listed in CISA KEV, implying no confirmed widespread exploitation as of now. The attack can be performed remotely by manipulating an HTTP parameter, so the likelihood of exploitation remains significant without remediation.

Generated by OpenCVE AI on September 30, 2026 at 17:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Restrict network access to the /admin/ endpoint by firewall rules or VPN only to trusted admin IPs.
  • Audit and patch the authorization logic in /admin/ to perform server‑side validation that the requester’s role matches the requested ID; reject any mismatched request.
  • Monitor administrative logs for anomalous ID changes and set alerts to detect potential exploitation attempts.

Generated by OpenCVE AI on September 30, 2026 at 17:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This impacts an unknown function of the file /admin/ of the component Admin Area. Such manipulation of the argument ID leads to authorization bypass. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title AdithyaYelloju Restaurant-Management-System Admin Area admin authorization
First Time appeared Adithyayelloju
Adithyayelloju restaurant-management-system
Weaknesses CWE-285
CWE-639
CPEs cpe:2.3:a:adithyayelloju:restaurant-management-system:*:*:*:*:*:*:*:*
Vendors & Products Adithyayelloju
Adithyayelloju restaurant-management-system
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Adithyayelloju Restaurant-management-system
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-30T16:30:09.762Z

Reserved: 2026-09-30T08:09:24.003Z

Link: CVE-2026-103233

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-30T17:16:42.177

Modified: 2026-09-30T17:32:07.107

Link: CVE-2026-103233

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T17:15:17Z

Weaknesses
  • CWE-285

    Improper Authorization

  • CWE-639

    Authorization Bypass Through User-Controlled Key