CVE-2026-5157: code-projects Online Food Ordering System Order order.php cross site scripting
A vulnerability was identified in code-projects Online Food Ordering System 1.0. Affected is an unknown function of the file /form/order.php of the component Order Module. Such manipulation of the argument custid leads to cross site scripting. The attack may be performed from remote. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5157?
CVE-2026-5157 is classified as a medium severity vulnerability due to the potential for cross-site scripting attacks.
How do I fix CVE-2026-5157?
To mitigate CVE-2026-5157, ensure proper sanitization and validation of user inputs in the order.php file.
Which component is affected by CVE-2026-5157?
CVE-2026-5157 affects the Order Module of the code-projects Online Food Ordering System version 1.0.
What is the attack vector for CVE-2026-5157?
The attack vector for CVE-2026-5157 involves manipulating the cust_id parameter in the order.php file.
What type of vulnerability is CVE-2026-5157?
CVE-2026-5157 is a cross-site scripting (XSS) vulnerability.