CVE-2026-2136: projectworlds Online Food Ordering System view-ticket.php sql injection
A flaw has been found in projectworlds Online Food Ordering System 1.0. This affects an unknown function of the file /view-ticket.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2136?
The severity of CVE-2026-2136 is classified as high due to its potential for SQL injection exploits.
How do I fix CVE-2026-2136?
To fix CVE-2026-2136, ensure proper input validation and sanitization on the ID parameter in view-ticket.php.
What type of vulnerability is CVE-2026-2136?
CVE-2026-2136 is an SQL injection vulnerability that can be exploited through the view-ticket.php file.
Which version of the Online Food Ordering System is affected by CVE-2026-2136?
CVE-2026-2136 affects version 1.0 of the projectworlds Online Food Ordering System.
What can attackers do with CVE-2026-2136?
Attackers can manipulate the ID argument in view-ticket.php to execute arbitrary SQL queries, potentially compromising the database.