CVE-2026-78248: SourceCodester Simple Online Food Ordering System ajax.php save_settings sql injection
A vulnerability was determined in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/admin/ajax.php?action=savesettings. This manipulation of the argument Name causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The issue can be exploited remotely and requires no privileges or user interaction according to the supplied severity vector. An attacker can target the affected ajax.php save_settings endpoint over the network.
Is exploit code available?
Yes. The exploit has been publicly disclosed and may be used by attackers.
What input is implicated in the SQL injection?
The vulnerable endpoint is /fos/admin/ajax.php?action=save_settings, and the affected argument is Name. The supplied data does not identify the specific underlying function or additional affected parameters.