Impact
A vulnerability exists in SourceCodester Simple Online Food Ordering System 1.0 that allows manipulation of the ID parameter in the /fos/view_prod.php file, causing a SQL injection flaw. The description states that remote exploitation is possible, indicating that an attacker could send crafted requests over the network. Based on the description, it is inferred that such an injection could enable unauthorized database access, data exfiltration, or modification of application content, but the exact impact is not explicitly detailed.
Affected Systems
The affected product is SourceCodester Simple Online Food Ordering System version 1.0, specifically the /fos/view_prod.php functionality where the ID query parameter is improperly sanitized.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.9, indicating a moderate severity. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog. Attackers can exploit this flaw over the network, leveraging publicly available exploits. Based on the description and lack of an access control boundary, it is inferred that remote attackers could potentially retrieve or alter data stored in the system's database.
OpenCVE Enrichment