Junglewise Threat Intelligence

CVE-2026-14622: jairiidriss restaurant-website-php-mysql missing authentication in AJAX endpoints

CVE-2026-14622 · Severity: high · CVSS 7.3 · Published 2026-07-04

Executive brief

A vulnerability exists in the jairiidriss Restaurant Website software, which is used for online food ordering and table reservations. Due to a security flaw, the administrative dashboard's background functions do not verify if a user is logged in before performing sensitive actions. This allows an unauthorized person to remotely delete menu items, cancel customer orders, or modify website categories, potentially disrupting business operations and damaging the restaurant's reputation.

Technical details

A missing authentication vulnerability (CWE-306) exists in multiple administrative AJAX endpoints within the /admin/ajax_files/ directory, including menus_ajax.php, dashboard_ajax.php, and menu_categories_ajax.php. While the primary administrative UI enforces session checks, the underlying PHP scripts process POST requests directly without validating the administrator's session. A remote, unauthenticated attacker can exploit this by sending crafted POST requests to these endpoints to delete menu items, cancel or modify order statuses, and manage categories. The vulnerability is present up to commit 521428b and no official patch has been released by the vendor.

Affected products

  • jairiidriss restaurant-website-php-mysql up to 521428b5b612449df0cf4a5d15ee40cba67f3d35

Timeline

  • 2026-06-01: disclosed: Issue reported to the project maintainer on GitHub
  • 2026-07-04: advisory: CVE published by VulDB/NVD

References