CVE-2026-90854: SourceCodester/katojkalemba Online Food Ordering System category-foods.php sql injection
A security flaw has been discovered in SourceCodester/katojkalemba Online Food Ordering System 1.0. The impacted element is an unknown function of the file /web/category-foods.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The vulnerable category-foods.php endpoint can be attacked remotely by manipulating its ID argument. No authentication or user interaction is required according to the provided CVSS vector.
Is public exploit information available?
Yes. The exploit has been released publicly and may be used in attacks, increasing the likelihood of opportunistic exploitation.
What security impact could successful exploitation have?
The reported CVSS vector indicates low impacts to confidentiality, integrity, and availability. Because this is SQL injection, the affected application's database interactions through the vulnerable endpoint are at risk.