Impact
The source code of the Online Food Ordering System allows the include function in index.php to be controlled through the page parameter. Modifying this argument can force the application to include arbitrary local or remote files. As a result an attacker can inject malicious code or read sensitive data, leading to loss of confidentiality, integrity and potential complete system compromise.
Affected Systems
The vulnerability affects SourceCodester's Online Food Ordering System version 2.0, which is deployed on servers hosting the application. Any environment running this specific version is susceptible; no other versions were listed as affected in the available data.
Risk and Exploitability
The CVSS score of 6.9 classifies the issue as medium severity, and the exploit is publicly available via the page parameter in a remote request. While the EPSS score is not provided and the vulnerability is not listed in the CISA KEV catalog, the attack vector is remote, meaning that anyone with network access to the application could trigger it. Successful exploitation would provide attackers with remote code execution capabilities and access to local files, posing a significant threat to the affected system.
OpenCVE Enrichment