Impact
A flaw in the category-foods.php page allows an attacker to manipulate the ID argument, resulting in an SQL injection vulnerability. The weakness can lead to unauthorized reading or modification of database records, affecting the confidentiality and integrity of stored data.
Affected Systems
The affected applications are SourceCodester Online Food Ordering System and katojkalemba Online Food Ordering System, both released in version 1.0. The vulnerability resides in the file /web/category-foods.php of this release.
Risk and Exploitability
The flaw can be triggered remotely by supplying malicious input for the ID parameter; the security description does not mention an authentication requirement, so it is unclear if authentication is needed. Public exploits have been released, and the EPSS score of <1% indicates a low probability of widespread exploitation. The CVSS score of 6.9 reflects a medium risk that warrants prompt remediation, and the issue is not listed in the CISA KEV catalog.
OpenCVE Enrichment