CVE-2026-81203: SourceCodester Simple Online Food Ordering System ajax.php login2 sql injection
A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=login2. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
No authentication or user interaction is required. The vulnerable login endpoint can be targeted remotely by manipulating the email argument.
Is public exploit information available?
Yes. The exploit has been publicly disclosed, so organizations running the affected software should treat exploitation attempts as plausible.
Which deployments are affected?
The affected product is SourceCodester Simple Online Food Ordering System version 1.0. The issue is associated with the /admin/ajax.php?action=login2 endpoint.