Executive brief
SourceCodester Simple Online Food Ordering System is a web application for managing online food orders. An unauthenticated attacker can upload arbitrary files through the admin panel, potentially enabling remote code execution and compromising confidentiality, integrity, and availability of the system.
Technical details
This vulnerability is an unrestricted file upload flaw in the /admin/ajax.php endpoint with the save_menu action. The application fails to validate or sanitize uploaded files, allowing an attacker to upload dangerous file types without restrictions. The attack is remotely exploitable and does not require authentication. Successful exploitation allows arbitrary file upload which can lead to remote code execution if the uploaded files are processed by the application. The vulnerability is publicly known with exploit code available.
Affected products
- SourceCodester Simple Online Food Ordering System 1.0
Timeline
- 2026-07-05: disclosed
- 2026-08-20: advisory