CVE-2025-2387: SourceCodester Online Food Ordering System ajax.php sql injection
A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been classified as critical. Affected is an unknown function of the file /admin/ajax.php?action=addtocart. The manipulation of the argument pid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2387?
CVE-2025-2387 is classified as a critical vulnerability.
How do I fix CVE-2025-2387?
To fix CVE-2025-2387, validate and sanitize user inputs in the /admin/ajax.php?action=add_to_cart function to prevent SQL injection.
What systems are affected by CVE-2025-2387?
CVE-2025-2387 affects SourceCodester Online Food Ordering System version 2.0.
What type of vulnerability is CVE-2025-2387?
CVE-2025-2387 is an SQL injection vulnerability due to improper handling of the 'pid' argument.
Can CVE-2025-2387 be exploited remotely?
Yes, CVE-2025-2387 can be exploited remotely by sending crafted requests to the affected endpoint.