Impact
The vulnerability resides in the AdithyaYelloju Restaurant‑Management‑System, specifically in the unprotected admin interface at /admin/. An attacker can manipulate the ID argument to bypass authorization controls, gaining unauthorized access to privileged administrative functions. This flaw maps to authorization bypass (CWE‑285) and privilege escalation via control bypass (CWE‑639).
Affected Systems
The affected product is the Restaurant‑Management‑System by AdithyaYelloju. The flaw exists in code versions up to commit 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. No official patch is available yet, so any installation using the impacted code base is vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk. The EPSS score is not available, so the exploitation probability cannot be quantified, but a publicly disclosed exploit exists. The issue is not listed in CISA KEV, implying no confirmed widespread exploitation as of now. The attack can be performed remotely by manipulating an HTTP parameter, so the likelihood of exploitation remains significant without remediation.
OpenCVE Enrichment