Junglewise Threat Intelligence

CVE-2026-76995: SourceCodester Simple Online Food Ordering System unrestricted file upload

CVE-2026-76995 · Severity: medium · CVSS 4.7 · Published 2026-08-20

Technologies: SourceCodester Simple Online Food Ordering System. Vendors: SourceCodester.

Executive brief

SourceCodester Simple Online Food Ordering System is a web application for managing online food orders. An unauthenticated attacker can upload arbitrary files through the admin panel, potentially enabling remote code execution and compromising confidentiality, integrity, and availability of the system.

Technical details

This vulnerability is an unrestricted file upload flaw in the /admin/ajax.php endpoint with the save_menu action. The application fails to validate or sanitize uploaded files, allowing an attacker to upload dangerous file types without restrictions. The attack is remotely exploitable and does not require authentication. Successful exploitation allows arbitrary file upload which can lead to remote code execution if the uploaded files are processed by the application. The vulnerability is publicly known with exploit code available.

Affected products

  • SourceCodester Simple Online Food Ordering System 1.0

Timeline

  • 2026-07-05: disclosed
  • 2026-08-20: advisory

References

Related threats