CVE-2026-76996: SourceCodester Simple Online Food Ordering System view_order.php sql injection
A security flaw has been discovered in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/admin/vieworder.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker can exploit the SQL injection without authentication or user interaction, according to the supplied vector. The affected endpoint is /fos/admin/view_order.php, with the ID argument identified as the injection point.
Is public exploit code available?
Yes. The vulnerability data states that an exploit has been publicly released and may be used in attacks.
What impact could successful exploitation have?
The provided severity vector indicates low impacts to confidentiality, integrity, and availability. This means successful exploitation may allow limited disclosure, modification, or disruption.