CVE-2026-95868: AdithyaYelloju Restaurant-Management-System Search Form display_menu.php mysqli_query sql injection
A weakness has been identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Affected by this issue is the function mysqliquery of the file admin/displaymenu.php of the component Search Form. This manipulation of the argument s1 causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs network access to the application and a low-privileged account. No user interaction is required.
What access could exploitation provide?
The vulnerability is rated as having low confidentiality, integrity, and availability impact. Successful SQL injection could affect database data accessible through the vulnerable application's database permissions.
Is public exploitation available?
Yes. A public exploit has been made available, so the issue could be used in attacks.
Which releases are affected or fixed?
The affected code is reported through commit 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Because the project uses rolling releases, no affected or updated release versions are available.
Has the project provided a remediation response?
The project was notified through an issue report but had not responded at the time of the report. No vendor-provided fix is identified in the available data.