Impact
The vulnerability is an unauthenticated remote SQL injection in the admin/add_menu.php script of the Restaurant-Management-System. By manipulating the item, price, image or type parameters, an attacker can inject arbitrary SQL statements that are executed against the backend database, potentially allowing data disclosure, alteration, or denial of service. This flaw is a classic injection flaw classified under the CWEs for missing or incorrect user input handling and SQL injection.
Affected Systems
Affected products are the Restaurant-Management-System developed by AdithyaYelloju. No specific release notes or patch versions are publicly available, as the project uses a rolling release model and the latest known vulnerable commit is 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Administrators should therefore treat all current releases as vulnerable until an official fix is issued.
Risk and Exploitability
The CVSS base score is 5.3, reflecting a moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack can be launched remotely via the exposed add_menu.php endpoint, and the lack of a patch increases the risk. Without defensive controls, an attacker could execute arbitrary SQL and compromise the application’s data layer.
OpenCVE Enrichment