CVE-2026-103233: AdithyaYelloju Restaurant-Management-System Admin Area admin authorization
A security vulnerability has been detected in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This impacts an unknown function of the file /admin/ of the component Admin Area. Such manipulation of the argument ID leads to authorization bypass. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs network access to the affected application and low-privileged access, as indicated by the required privileges metric. No user interaction is required.
What is required for exploitation?
Exploitation involves manipulating an ID argument in an unknown function under /admin/. The attack can be performed remotely, and public exploit disclosure means exploit details may be available to attackers.
Is a fix available from the project?
The available information does not identify a fixed version. The project was notified through an issue report but had not responded at the time of publication.
What should teams do if they cannot patch immediately?
Restrict access to the /admin/ area to only trusted, authorized users and networks, and review authorization controls around ID-based requests. Monitor administrative requests for unexpected ID manipulation or access to records outside a user's intended scope.