CVE-2025-4507: Campcodes Online Food Ordering System add-item.php sql injection
A vulnerability classified as critical has been found in Campcodes Online Food Ordering System 1.0. This affects an unknown part of the file /routers/add-item.php. The manipulation of the argument price leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4507?
CVE-2025-4507 has been classified as a critical severity vulnerability.
How does CVE-2025-4507 affect the Online Food Ordering System?
CVE-2025-4507 affects the /routers/add-item.php file, allowing for SQL injection through manipulation of the price argument.
Can CVE-2025-4507 be exploited remotely?
Yes, CVE-2025-4507 can be exploited remotely by attackers.
What should I do to mitigate CVE-2025-4507?
To mitigate CVE-2025-4507, sanitize and validate inputs to the price argument in the application.
Is the Campcodes Online Food Ordering System 1.0 vulnerable to CVE-2025-4507?
Yes, Campcodes Online Food Ordering System 1.0 is vulnerable to CVE-2025-4507 due to the identified SQL injection risk.