Impact
A flaw in the Category Update component of SourceCodester Online Food Ordering System allows an attacker to inject malicious script through the update_category.php file. The vulnerability exploits an unknown function that does not properly validate or encode user input, giving the attacker the ability to run arbitrary JavaScript in the browsers of users who view the affected pages. This can lead to session hijacking, defacement, or information theft. The weakness is a typical case of reflected or stored cross‑site scripting (CWE‑79) combined with potential code injection (CWE‑94).
Affected Systems
SourceCodester Online Food Ordering System version 1.0, accessed via its administrative update_category.php interface.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate impact, and the EPSS score of less than 1% suggests a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog, implying no known active exploits. Attacks are initiated remotely by supplying crafted input to the update_category.php endpoint, with no additional privileges required beyond the ability to submit category updates. The risk is primarily confined to the victim’s browser session and does not grant direct server‑side compromise.
OpenCVE Enrichment