CVE-2026-14693: SourceCodester Multi-Vendor Online Grocery Management System Master.php cancel_order improper authorization
A flaw has been found in SourceCodester Multi-Vendor Online Grocery Management System 1.0. Affected by this vulnerability is the function cancelorder of the file classes/Master.php. Executing a manipulation can lead to improper authorization. The attack may be performed from remote. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14693?
CVE-2026-14693 has a medium severity rating of 5.4.
How do I fix CVE-2026-14693?
Fixing CVE-2026-14693 involves updating the SourceCodester Multi-Vendor Online Grocery Management System to the latest version that addresses the improper authorization flaw.
What is the risk level of CVE-2026-14693?
CVE-2026-14693 is classified with a risk score of 34.
What exploit vector does CVE-2026-14693 use?
CVE-2026-14693 can be exploited remotely through the cancel_order function in the Master.php file.
What type of vulnerability is CVE-2026-14693?
CVE-2026-14693 is an improper authorization vulnerability affecting the SourceCodester Multi-Vendor Online Grocery Management System.