CVE-2026-4844: code-projects Online Food Ordering System Admin Login admin.php sql injection
A vulnerability was detected in code-projects Online Food Ordering System 1.0. This issue affects some unknown processing of the file /admin.php of the component Admin Login Module. The manipulation of the argument Username results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4844?
CVE-2026-4844 has a medium severity level, indicating a moderate risk of exploitation.
How do I fix CVE-2026-4844?
To fix CVE-2026-4844, ensure that input validation and parameterized queries are implemented in the admin.php file.
What components are affected by CVE-2026-4844?
CVE-2026-4844 affects the Admin Login Module of code-projects Online Food Ordering System version 1.0.
What type of vulnerability is described in CVE-2026-4844?
CVE-2026-4844 is an SQL injection vulnerability that allows unauthorized access to the system.
Can CVE-2026-4844 lead to data breaches?
Yes, CVE-2026-4844 can lead to data breaches by allowing attackers to manipulate the database via the admin login.