Junglewise Threat Intelligence

CVE-2026-14693: SourceCodester Multi-Vendor Online Grocery Management System IDOR in cancel_order

CVE-2026-14693 · Severity: medium · CVSS 5.4 · Published 2026-07-05

Technologies: SourceCodester Multi-Vendor Online Grocery Management System. Vendors: SourceCodester.

Executive brief

SourceCodester Multi-Vendor Online Grocery Management System is a web application for managing grocery sales. A security flaw allows any registered customer to cancel or modify the status of orders belonging to other users. This could lead to business disruption, targeted sabotage of competitors, and loss of customer trust.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the cancel_order function within classes/Master.php. The application accepts an order ID via POST data and executes a database UPDATE statement without verifying if the order belongs to the currently authenticated user. Because client registration is open to the public without approval, any remote attacker can create an account and manipulate the 'id' parameter to cancel arbitrary orders. The update_status function is reportedly affected by the same lack of ownership validation. No official patch is currently available; developers are advised to enforce ownership by including the session-based client_id in the SQL WHERE clause.

Affected products

  • SourceCodester Multi-Vendor Online Grocery Management System 1.0

Timeline

  • 2026-06-03: disclosed: Vulnerability details and PoC published on GitHub
  • 2026-07-05: advisory: NVD/VulDB advisory published

References

Related threats