Description
A security vulnerability has been detected in itsourcecode Online Frozen Foods Ordering System 1.0. This vulnerability affects unknown code of the file /admin/admin_edit_supplier.php. The manipulation of the argument Supplier_Name leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.
Published: 2026-03-20
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection
Action: Immediate Patch
AI Analysis

Impact

A flaw in the admin_edit_supplier.php page of the Online Frozen Foods Ordering System allows an attacker to inject arbitrary SQL through the Supplier_Name field. Because the input is concatenated directly into a database query, a malicious user can read, modify, or delete supplier records and potentially access other database objects. This read/write capability threatens the confidentiality, integrity, and availability of the ordering system’s data.

Affected Systems

The vulnerability affects itsourcecode’s Online Frozen Foods Ordering System version 1.0. No other versions are listed as affected. The flaw exists in the administrative supplier editing interface.

Risk and Exploitability

The CVSS score of 5.3 denotes moderate severity, while an EPSS score of less than 1% indicates a very low probability of widespread exploitation in the general population. The vulnerability is not in the CISA KEV catalog. The attack can be started remotely with HTTP access, and a public exploit is available, meaning any user who can reach the admin page could potentially inject SQL without authentication. No advanced prerequisites are required beyond remote web access.

Generated by OpenCVE AI on March 23, 2026 at 18:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s official patch or upgrade to a newer release of the Online Frozen Foods Ordering System when it becomes available.
  • Restrict access to the /admin/admin_edit_supplier.php page to trusted IP addresses or enforce strict role‑based authentication.
  • Implement input validation or use parameterized queries to avoid direct SQL string concatenation for Supplier_Name.
  • Deploy a web application firewall or similar intrusion detection system to block common SQL injection payloads.
  • Monitor application logs for unusual or failed database queries and investigate any suspicious activity promptly.

Generated by OpenCVE AI on March 23, 2026 at 18:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 23 Mar 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Adonesevangelista
Adonesevangelista online Frozen Foods Ordering System
CPEs cpe:2.3:a:adonesevangelista:online_frozen_foods_ordering_system:1.0:*:*:*:*:*:*:*
Vendors & Products Adonesevangelista
Adonesevangelista online Frozen Foods Ordering System

Fri, 20 Mar 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 20 Mar 2026 05:15:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in itsourcecode Online Frozen Foods Ordering System 1.0. This vulnerability affects unknown code of the file /admin/admin_edit_supplier.php. The manipulation of the argument Supplier_Name leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.
Title itsourcecode Online Frozen Foods Ordering System admin_edit_supplier.php sql injection
First Time appeared Itsourcecode
Itsourcecode online Frozen Foods Ordering System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:itsourcecode:online_frozen_foods_ordering_system:*:*:*:*:*:*:*:*
Vendors & Products Itsourcecode
Itsourcecode online Frozen Foods Ordering System
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Adonesevangelista Online Frozen Foods Ordering System
Itsourcecode Online Frozen Foods Ordering System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-03-20T20:01:56.534Z

Reserved: 2026-03-19T20:35:15.993Z

Link: CVE-2026-4472

cve-icon Vulnrichment

Updated: 2026-03-20T20:01:53.000Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-20T05:16:17.067

Modified: 2026-03-23T17:16:15.773

Link: CVE-2026-4472

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-25T14:30:27Z

Weaknesses