Description
A security flaw has been discovered in SourceCodester/katojkalemba Online Food Ordering System 1.0. The impacted element is an unknown function of the file /web/category-foods.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
Published: 2026-09-15
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL injection
Action: Apply patch
AI Analysis

Impact

A flaw in the category-foods.php page allows an attacker to manipulate the ID argument, resulting in an SQL injection vulnerability. The weakness can lead to unauthorized reading or modification of database records, affecting the confidentiality and integrity of stored data.

Affected Systems

The affected applications are SourceCodester Online Food Ordering System and katojkalemba Online Food Ordering System, both released in version 1.0. The vulnerability resides in the file /web/category-foods.php of this release.

Risk and Exploitability

The flaw can be triggered remotely by supplying malicious input for the ID parameter; the security description does not mention an authentication requirement, so it is unclear if authentication is needed. Public exploits have been released, and the EPSS score of <1% indicates a low probability of widespread exploitation. The CVSS score of 6.9 reflects a medium risk that warrants prompt remediation, and the issue is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 17, 2026 at 19:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Acquire and install the latest official update or patch for the Online Food Ordering System.
  • Modify the handling of the ID parameter in category‑foods.php to employ prepared statements or parameterized queries, preventing arbitrary SQL execution.
  • Enforce strict input validation on the ID field, ensuring only acceptable numeric values are processed, and reject any non‑conforming input.
  • Restrict unauthenticated access to the affected page or require authentication, and deploy a web application firewall to block common SQL injection payloads.

Generated by OpenCVE AI on September 17, 2026 at 19:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in SourceCodester/katojkalemba Online Food Ordering System 1.0. The impacted element is an unknown function of the file /web/category-foods.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
Title SourceCodester/katojkalemba Online Food Ordering System category-foods.php sql injection
First Time appeared Katojkalemba
Katojkalemba online Food Ordering System
Sourcecodester
Sourcecodester online Food Ordering System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:katojkalemba:online_food_ordering_system:*:*:*:*:*:*:*:*
cpe:2.3:a:sourcecodester:online_food_ordering_system:*:*:*:*:*:*:*:*
Vendors & Products Katojkalemba
Katojkalemba online Food Ordering System
Sourcecodester
Sourcecodester online Food Ordering System
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Katojkalemba Online Food Ordering System
Sourcecodester Online Food Ordering System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T16:57:48.935Z

Reserved: 2026-09-14T05:42:03.657Z

Link: CVE-2026-90854

cve-icon Vulnrichment

Updated: 2026-09-16T16:57:43.064Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T03:17:06.560

Modified: 2026-09-16T17:18:18.527

Link: CVE-2026-90854

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:00:17Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')