Impact
The flaw in SourceCodester Simple Online Food Ordering System version 1.0 allows an attacker to manipulate the Username parameter in the /admin/ajax.php?action=login endpoint, resulting in a remote SQL injection. This weakness, identified as CWE‑89 and CWE‑74, could enable unauthorized access to, modification of, or deletion of database contents, compromising the confidentiality and integrity of sensitive user data. The vendor’s description indicates that the flaw is publicly exploitable and that an exploit has already been published.
Affected Systems
The vulnerability affects the SourceCodester Simple Online Food Ordering System 1.0, specifically the admin login functionality accessed via /admin/ajax.php. No additional affected versions are listed in the available data.
Risk and Exploitability
The CVSS score of 6.9 assigns this flaw a medium severity level. Although the EPSS score is not available, the lack of a KEV listing does not eliminate exploitation risk; an attacker can launch the attack remotely by issuing a crafted Username in the login request, and published exploits are already in circulation. Since a vendor patch is not publicly documented, organizations must rely on mitigation measures to reduce the risk.
OpenCVE Enrichment