Impact
The vulnerability is a classic SQL Injection in the Username field of the save_customer action of the Online Food Ordering System version 1.0. An attacker can embed malicious SQL code, potentially allowing them to read, modify, or delete data from the database. This weakness directly compromises confidentiality and integrity of the underlying data store.
Affected Systems
The affected product is Online Food Ordering System 1.0, developed by Oretnom23, as identified by the base CPE string for that application.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical level of severity. The EPSS score below 1% suggests a low probability of exploitation in the wild, and the vulnerability is not yet listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is remote, via an unauthenticated HTTP request that supplies a crafted username value.
OpenCVE Enrichment