Description
A vulnerability has been found in SourceCodester Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/update_category.php of the component Category Update. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Published: 2026-09-16
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: cross‑site scripting
Action: Patch
AI Analysis

Impact

A flaw in the Category Update component of SourceCodester Online Food Ordering System allows an attacker to inject malicious script through the update_category.php file. The vulnerability exploits an unknown function that does not properly validate or encode user input, giving the attacker the ability to run arbitrary JavaScript in the browsers of users who view the affected pages. This can lead to session hijacking, defacement, or information theft. The weakness is a typical case of reflected or stored cross‑site scripting (CWE‑79) combined with potential code injection (CWE‑94).

Affected Systems

SourceCodester Online Food Ordering System version 1.0, accessed via its administrative update_category.php interface.

Risk and Exploitability

The CVSS score of 4.8 indicates a moderate impact, and the EPSS score of less than 1% suggests a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog, implying no known active exploits. Attacks are initiated remotely by supplying crafted input to the update_category.php endpoint, with no additional privileges required beyond the ability to submit category updates. The risk is primarily confined to the victim’s browser session and does not grant direct server‑side compromise.

Generated by OpenCVE AI on September 18, 2026 at 05:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a vendor‑issued patch or upgrade the application to the latest released version that addresses the input validation issue.
  • Sanitize all user‑supplied data in the category update process and perform context‑sensitive output encoding before rendering to prevent script execution.
  • Implement a strict Content Security Policy to limit the execution of unexpected scripts and to mitigate the impact of any residual XSS attempts.

Generated by OpenCVE AI on September 18, 2026 at 05:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in SourceCodester Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/update_category.php of the component Category Update. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Title SourceCodester Online Food Ordering System Category Update update_category.php cross site scripting
First Time appeared Sourcecodester
Sourcecodester online Food Ordering System
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:sourcecodester:online_food_ordering_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester online Food Ordering System
References
Metrics cvssV2_0

{'score': 3.3, 'vector': 'AV:N/AC:L/Au:M/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 2.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 2.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Online Food Ordering System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-22T16:07:59.419Z

Reserved: 2026-09-16T08:08:25.000Z

Link: CVE-2026-92385

cve-icon Vulnrichment

Updated: 2026-09-22T16:05:51.398Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T16:17:22.767

Modified: 2026-09-22T17:17:29.753

Link: CVE-2026-92385

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T19:30:12Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')