Impact
The vulnerability is a SQL injection flaw in delete_food_items1.php of the Online Food Order System. By manipulating the checkbox argument, an attacker can inject arbitrary SQL code, allowing remote execution of commands that may alter or delete data. The flaw corresponds to CWE-74 and CWE-89.
Affected Systems
Versions 1.0 of code-projects Online Food Order System are affected. The flaw occurs in delete_food_items1.php, and no other product editions or versions are mentioned.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score is not available; however, an exploit has been published and can be performed remotely. The vulnerability is known but not listed in CISA KEV, suggesting limited but possible exploitation if the system is publicly reachable.
OpenCVE Enrichment