CVE-2026-30531: SQL Injection
Published Mar 27, 2026
·Updated
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the savecategory action). The application fails to properly sanitize user input supplied to the "name" parameter. This allows an authenticated attacker to inject malicious SQL commands.
Affected Software
2 affected components
Sourcecodester Online Food Ordering System=1.0
oretnom23 Online Food Ordering System=1.0
Event History
Mar 27, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software