CVE-2026-78199: SourceCodester Simple Online Food Ordering System view_prod.php sql injection
A vulnerability was detected in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/viewprod.php. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
An attacker can exploit the issue remotely over the network. No privileges or user interaction are required according to the supplied vector.
Which component should be prioritized for investigation?
Investigation should focus on the /fos/view_prod.php endpoint and its ID argument, where manipulation is reported to result in SQL injection.
How urgent is remediation?
Remediation should be prioritized because the vulnerability is rated high severity and a public exploit is available. The reported impacts include loss of confidentiality, integrity, and availability.