CVE-2026-76998: SourceCodester Simple Online Food Ordering System ajax.php delete_category sql injection
A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/ajax.php?action=deletecategory. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The attack can be launched remotely and requires no privileges or user interaction, according to the supplied CVSS vector. A public exploit has been disclosed, increasing the likelihood of attempted exploitation.
What input and endpoint are involved?
The affected request is /admin/ajax.php?action=delete_category. SQL injection occurs through manipulation of the ID argument.
Which versions are affected?
The provided information identifies SourceCodester Simple Online Food Ordering System version 1.0. No other affected or fixed versions are specified.