Impact
The vulnerability resides in SourceCodester Simple Online Food Ordering System 1.0 within the /admin/ajax.php file for the login2 action. The email argument can be manipulated to inject arbitrary SQL statements, allowing an attacker to execute unintended queries. This could compromise confidentiality, integrity, and availability of the system’s data.
Affected Systems
The affected product is SourceCodester Simple Online Food Ordering System version 1.0. All installations of this version are impacted.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. It can be triggered remotely from any network location without requiring prior authentication, giving adversaries an accessible attack vector.
OpenCVE Enrichment