Description
A weakness has been identified in itsourcecode Online Frozen Foods Ordering System 1.0. This affects an unknown part of the file /admin/admin_edit_employee.php. Executing a manipulation of the argument First_Name can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.
Published: 2026-03-20
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection
Action: Patch Now
AI Analysis

Impact

A flaw in the admin_edit_employee.php page allows attackers to inject arbitrary SQL by manipulating the First_Name parameter. This can modify or read database contents, potentially exposing or tampering with employee records and compromising the integrity and confidentiality of the system.

Affected Systems

The vulnerability targets itsourcecode Online Frozen Foods Ordering System version 1.0, specifically the /admin/admin_edit_employee.php script. No other versions or components were identified as affected.

Risk and Exploitability

With a CVSS score of 5.1 the issue is of moderate severity, yet the EPSS score of less than 1% indicates a low likelihood of widespread exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, but an attacker can launch the exploit remotely using publicly available proof‑of‑concept code. Administrators should consider it a tangible threat until a patch or mitigation is in place.

Generated by OpenCVE AI on March 23, 2026 at 18:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Confirm the system is running version 1.0 of itsourcecode Online Frozen Foods Ordering System.
  • Apply any vendor‑provided patch or update that addresses the SQL injection in admin_edit_employee.php.
  • If no patch is available, restrict external access to /admin/admin_edit_employee.php via firewall rules or IP whitelisting.
  • Validate and sanitize input for the First_Name field, using parameterized queries or prepared statements.
  • Deploy a web application firewall to detect and block SQL injection attempts.

Generated by OpenCVE AI on March 23, 2026 at 18:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 23 Mar 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Adonesevangelista
Adonesevangelista online Frozen Foods Ordering System
CPEs cpe:2.3:a:adonesevangelista:online_frozen_foods_ordering_system:1.0:*:*:*:*:*:*:*
Vendors & Products Adonesevangelista
Adonesevangelista online Frozen Foods Ordering System

Fri, 20 Mar 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 20 Mar 2026 05:15:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in itsourcecode Online Frozen Foods Ordering System 1.0. This affects an unknown part of the file /admin/admin_edit_employee.php. Executing a manipulation of the argument First_Name can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.
Title itsourcecode Online Frozen Foods Ordering System admin_edit_employee.php sql injection
First Time appeared Itsourcecode
Itsourcecode online Frozen Foods Ordering System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:itsourcecode:online_frozen_foods_ordering_system:*:*:*:*:*:*:*:*
Vendors & Products Itsourcecode
Itsourcecode online Frozen Foods Ordering System
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Adonesevangelista Online Frozen Foods Ordering System
Itsourcecode Online Frozen Foods Ordering System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-03-20T18:08:00.880Z

Reserved: 2026-03-19T20:35:12.908Z

Link: CVE-2026-4471

cve-icon Vulnrichment

Updated: 2026-03-20T17:38:48.870Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-20T05:16:16.857

Modified: 2026-03-23T17:17:21.133

Link: CVE-2026-4471

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-25T14:30:28Z

Weaknesses