Description
A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. Affected by this issue is the function include of the file /index.php. The manipulation of the argument page results in file inclusion. The attack can be launched remotely. The exploit is now public and may be used.
Published: 2026-06-03
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The source code of the Online Food Ordering System allows the include function in index.php to be controlled through the page parameter. Modifying this argument can force the application to include arbitrary local or remote files. As a result an attacker can inject malicious code or read sensitive data, leading to loss of confidentiality, integrity and potential complete system compromise.

Affected Systems

The vulnerability affects SourceCodester's Online Food Ordering System version 2.0, which is deployed on servers hosting the application. Any environment running this specific version is susceptible; no other versions were listed as affected in the available data.

Risk and Exploitability

The CVSS score of 6.9 classifies the issue as medium severity, and the exploit is publicly available via the page parameter in a remote request. While the EPSS score is not provided and the vulnerability is not listed in the CISA KEV catalog, the attack vector is remote, meaning that anyone with network access to the application could trigger it. Successful exploitation would provide attackers with remote code execution capabilities and access to local files, posing a significant threat to the affected system.

Generated by OpenCVE AI on June 3, 2026 at 03:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SourceCodester Online Food Ordering System to the latest released version that contains the fix for the include vulnerability.
  • If an immediate upgrade is not possible, enforce strict input validation on the page parameter, allowing only a predefined list of safe page identifiers or employ directory traversal checks to prevent inclusion of arbitrary paths.
  • As a temporary measure, block or remove the page query parameter by configuring the web server or deploying a WAF rule to reject requests containing a page argument.

Generated by OpenCVE AI on June 3, 2026 at 03:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 03 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 03 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. Affected by this issue is the function include of the file /index.php. The manipulation of the argument page results in file inclusion. The attack can be launched remotely. The exploit is now public and may be used.
Title SourceCodester Online Food Ordering System index.php include file inclusion
First Time appeared Sourcecodester
Sourcecodester online Food Ordering System
Weaknesses CWE-73
CPEs cpe:2.3:a:sourcecodester:online_food_ordering_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester online Food Ordering System
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Online Food Ordering System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-06-03T12:29:00.364Z

Reserved: 2026-06-02T15:47:06.210Z

Link: CVE-2026-10694

cve-icon Vulnrichment

Updated: 2026-06-03T12:28:55.528Z

cve-icon NVD

Status : Received

Published: 2026-06-03T01:16:23.083

Modified: 2026-06-03T01:16:23.083

Link: CVE-2026-10694

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-03T03:45:23Z

Weaknesses