CVE-2026-92385: SourceCodester Online Food Ordering System Category Update update_category.php cross site scripting
A vulnerability has been found in SourceCodester Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/updatecategory.php of the component Category Update. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need?
The CVSS vector indicates that exploitation requires high privileges. Although the attack can be initiated remotely, it is not an unauthenticated attack.
What impact can successful exploitation have?
The reported impact is limited to integrity, with no reported confidentiality or availability impact. Exploitation also requires user interaction, consistent with an XSS scenario where a victim must interact with attacker-controlled content.
How urgent is remediation?
A public exploit has been disclosed, so affected deployments should be prioritized for remediation despite the low 2.4 severity score. The affected product version identified in the report is SourceCodester Online Food Ordering System 1.0.