Description
A vulnerability has been found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Affected by this issue is some unknown functionality of the file admin/add_menu.php. The manipulation of the argument item/price/image/type leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-20
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection
Action: Apply Fix
AI Analysis

Impact

The vulnerability is an unauthenticated remote SQL injection in the admin/add_menu.php script of the Restaurant-Management-System. By manipulating the item, price, image or type parameters, an attacker can inject arbitrary SQL statements that are executed against the backend database, potentially allowing data disclosure, alteration, or denial of service. This flaw is a classic injection flaw classified under the CWEs for missing or incorrect user input handling and SQL injection.

Affected Systems

Affected products are the Restaurant-Management-System developed by AdithyaYelloju. No specific release notes or patch versions are publicly available, as the project uses a rolling release model and the latest known vulnerable commit is 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Administrators should therefore treat all current releases as vulnerable until an official fix is issued.

Risk and Exploitability

The CVSS base score is 5.3, reflecting a moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack can be launched remotely via the exposed add_menu.php endpoint, and the lack of a patch increases the risk. Without defensive controls, an attacker could execute arbitrary SQL and compromise the application’s data layer.

Generated by OpenCVE AI on September 20, 2026 at 18:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Disable or restrict access to the admin/add_menu.php page until an official fix is released
  • Implement strict input validation or use prepared statements for the item, price, image, and type parameters to prevent malicious SQL injection
  • Deploy a web application firewall or intrusion detection system to block suspicious query patterns and monitor database logs for abnormal activity

Generated by OpenCVE AI on September 20, 2026 at 18:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Affected by this issue is some unknown functionality of the file admin/add_menu.php. The manipulation of the argument item/price/image/type leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Title AdithyaYelloju Restaurant-Management-System add_menu.php sql injection
First Time appeared Adithyayelloju
Adithyayelloju restaurant-management-system
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:adithyayelloju:restaurant-management-system:*:*:*:*:*:*:*:*
Vendors & Products Adithyayelloju
Adithyayelloju restaurant-management-system
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Adithyayelloju Restaurant-management-system
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-21T16:26:29.154Z

Reserved: 2026-09-19T21:19:45.708Z

Link: CVE-2026-94041

cve-icon Vulnrichment

Updated: 2026-09-21T16:26:23.849Z

cve-icon NVD

Status : Deferred

Published: 2026-09-20T18:16:54.583

Modified: 2026-09-21T17:19:18.990

Link: CVE-2026-94041

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:02:24Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')