CVE-2026-4533: code-projects Simple Food Ordering System all-tickets.php sql injection
A vulnerability was detected in code-projects Simple Food Ordering System 1.0. Affected by this issue is some unknown functionality of the file all-tickets.php. The manipulation of the argument Status results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4533?
The severity of CVE-2026-4533 is classified as critical due to its potential for SQL injection which can lead to unauthorized access to the database.
How do I fix CVE-2026-4533?
To fix CVE-2026-4533, you should validate and sanitize all user inputs in the all-tickets.php file to prevent SQL injection.
What is affected by CVE-2026-4533?
CVE-2026-4533 affects version 1.0 of the Code-Projects Simple Food Ordering System, specifically the all-tickets.php functionality.
Can CVE-2026-4533 be exploited remotely?
Yes, CVE-2026-4533 can be exploited remotely if an attacker sends a crafted request to the vulnerable all-tickets.php file.
Are there any known exploits for CVE-2026-4533?
Yes, there are known exploits for CVE-2026-4533 that target the SQL injection vulnerability in the all-tickets.php file.