CVE-2026-4470: itsourcecode Online Frozen Foods Ordering System admin_edit_menu.php sql injection
A security flaw has been discovered in itsourcecode Online Frozen Foods Ordering System 1.0. Affected by this issue is some unknown functionality of the file /admin/admineditmenu.php. Performing a manipulation of the argument productname results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4470?
CVE-2026-4470 has been classified as a critical vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2026-4470?
To mitigate CVE-2026-4470, update the itsourcecode Online Frozen Foods Ordering System to a patched version or implement input validation and parameterized queries in admin_edit_menu.php.
Which version is affected by CVE-2026-4470?
CVE-2026-4470 affects version 1.0 of the itsourcecode Online Frozen Foods Ordering System.
What type of vulnerability is CVE-2026-4470?
CVE-2026-4470 is classified as an SQL injection vulnerability.
Where is CVE-2026-4470 located in the application?
CVE-2026-4470 is found in the file /admin/admin_edit_menu.php of the itsourcecode Online Frozen Foods Ordering System.