CVE-2026-5018: code-projects Simple Food Order System Parameter register-router.php sql injection
A weakness has been identified in code-projects Simple Food Order System 1.0. Affected is an unknown function of the file register-router.php of the component Parameter Handler. Executing a manipulation of the argument Name can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5018?
CVE-2026-5018 is classified as a critical vulnerability due to its potential for SQL injection, which can allow attackers to compromise the database.
How do I fix CVE-2026-5018?
To fix CVE-2026-5018, sanitize and validate all user inputs in the register-router.php file to prevent SQL injection attacks.
What software is affected by CVE-2026-5018?
CVE-2026-5018 affects version 1.0 of the code-projects Simple Food Order System.
What impact does CVE-2026-5018 have on my system?
CVE-2026-5018 can lead to unauthorized access to the database and manipulation of data, which could result in data loss or corruption.
Is CVE-2026-5018 actively being exploited?
There is no public information confirming active exploitation of CVE-2026-5018, but the nature of SQL injection vulnerabilities makes them highly concerning.