Description
A vulnerability was identified in itsourcecode Online Frozen Foods Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin_edit_menu_action.php. Such manipulation of the argument product_name leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.
Published: 2026-03-20
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL injection via product_name parameter
Action: Patch Now
AI Analysis

Impact

The flaw in the admin_edit_menu_action.php script allows an attacker to inject arbitrary SQL through the product_name parameter. The injection is triggered by manipulating the argument, and the vulnerability can be exploited from a remote client. Based on the description, it is inferred that an attacker could execute arbitrary SQL statements against the application database, potentially allowing data disclosure, modification, or loss. The impact covers confidentiality, integrity, and potentially availability of the ordering system.

Affected Systems

This vulnerability affects itsourcecode’s Online Frozen Foods Ordering System version 1.0, as well as the variant listed under adonesevangelista version 1.0. Any deployment of these releases that exposes the admin interface to external traffic is susceptible.

Risk and Exploitability

The CVSS score of 5.1 indicates medium severity, while the EPSS score of less than 1 % suggests a low probability of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. It can be executed remotely via crafted input to the product_name parameter, and a publicly available exploit exists, meaning unpatched installations could be targeted by attackers from outside the network.

Generated by OpenCVE AI on March 23, 2026 at 19:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s latest patch or upgrade to a newer release of the Online Frozen Foods Ordering System.
  • If a patch is not yet available, limit external access to the admin panel using firewall rules or VPN‑only access.
  • Review the application code to enforce proper input validation and use parameterized queries or an ORM for the product_name parameter to eliminate SQL injection risk.

Generated by OpenCVE AI on March 23, 2026 at 19:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 24 Mar 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 23 Mar 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Adonesevangelista
Adonesevangelista online Frozen Foods Ordering System
CPEs cpe:2.3:a:adonesevangelista:online_frozen_foods_ordering_system:1.0:*:*:*:*:*:*:*
Vendors & Products Adonesevangelista
Adonesevangelista online Frozen Foods Ordering System

Fri, 20 Mar 2026 04:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in itsourcecode Online Frozen Foods Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin_edit_menu_action.php. Such manipulation of the argument product_name leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.
Title itsourcecode Online Frozen Foods Ordering System admin_edit_menu_action.php sql injection
First Time appeared Itsourcecode
Itsourcecode online Frozen Foods Ordering System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:itsourcecode:online_frozen_foods_ordering_system:*:*:*:*:*:*:*:*
Vendors & Products Itsourcecode
Itsourcecode online Frozen Foods Ordering System
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Adonesevangelista Online Frozen Foods Ordering System
Itsourcecode Online Frozen Foods Ordering System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-03-24T01:46:27.757Z

Reserved: 2026-03-19T20:35:06.034Z

Link: CVE-2026-4469

cve-icon Vulnrichment

Updated: 2026-03-24T01:46:23.785Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-20T05:16:16.420

Modified: 2026-03-23T17:28:54.353

Link: CVE-2026-4469

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-25T14:09:23Z

Weaknesses