Executive brief
SourceCodester Simple Food Ordering System is a web application used for managing food orders. A vulnerability in the shopping cart allows customers to modify the price of items before adding them to their cart. This could allow an attacker to purchase products for free, at a significant discount, or even with negative totals, leading to financial loss and corrupted order records.
Technical details
A business logic vulnerability exists in SourceCodester Simple Food Ordering System 1.0 due to improper client-side price trust (CWE-602). The application accepts the 'item_price' POST parameter in 'cart.php' and uses it directly for calculations and order processing without verifying it against the authoritative price stored in the database. A remote, unauthenticated attacker can intercept the Add-to-Cart request and modify the price to any value, including zero or negative numbers. This allows for unauthorized discounts and the creation of fraudulent orders. No patch is currently known to be available.
Affected products
- SourceCodester Simple Food Ordering System 1.0
Timeline
- 2026-06-29: disclosed: Vulnerability details and PoC published on GitHub.
- 2026-06-29: advisory: CVE-2026-13571 published.