Impact
A flaw in the order.php script allows a remote attacker to manipulate the ID argument and inject arbitrary SQL statements. The injection bypasses input filtering, enabling the attacker to read sensitive order records or modify database entries, thereby compromising confidentiality, integrity, and potentially availability of the food ordering system.
Affected Systems
Both SourceCodester and katojkalemba distribute the Online Food Ordering System, version 1.0. Any deployment that exposes the order.php endpoint is subject to this vulnerability.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity. The EPSS score of less than 1% suggests a very low probability of exploitation, and the vulnerability is not listed in CISA's KEV catalog. Nonetheless, the publicly available exploit and remote attack vector via order.php provide a tangible risk for affected installations.
OpenCVE Enrichment