Impact
The vulnerability resides in an undeclared function within the /admin/ajax.php file of SourceCodester Simple Online Food Ordering System 1.0, where manipulating the id argument allows a remote attacker to inject arbitrary SQL statements. This flaw can lead to the unauthorized reading, alteration, or deletion of database contents, compromising the confidentiality, integrity, and availability of the application data.
Affected Systems
The affected product is SourceCodester Simple Online Food Ordering System, version 1.0. No other versions or vendors were listed as affected by the CNA for this CVE.
Risk and Exploitability
The flaw carries a CVSS score of 5.3, indicating a medium severity. The EPSS score is unavailable, but the vulnerability has been publicly disclosed and a working exploit exists, suggesting a realistic likelihood of exploitation. The issue is not currently listed in CISA’s KEV catalog, yet the remote nature of the attack vector and the severity of potential data compromise warrant careful attention.
OpenCVE Enrichment