CVE-2026-78198: SourceCodester Simple Online Food Ordering System ajax.php add_to_cart sql injection
A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=addtocart. Such manipulation of the argument pid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack can be launched remotely and does not require privileges or user interaction according to the supplied severity vector. The publicly disclosed exploit may make exploitation more likely.
Which deployments should be treated as potentially affected?
SourceCodester Simple Online Food Ordering System version 1.0 should be treated as affected where the /fos/admin/ajax.php?action=add_to_cart endpoint is exposed. The vulnerable input is the pid argument.
What is the potential impact of successful exploitation?
The severity vector indicates low impact to confidentiality, integrity, and availability. Because the flaw is SQL injection, successful exploitation could affect data handled by the application's database.