Junglewise Threat Intelligence

CVE-2026-76998: SourceCodester Simple Online Food Ordering System SQL injection in delete_category

CVE-2026-76998 · Severity: high · CVSS 7.3 · Published 2026-08-20

Technologies: SourceCodester Simple Online Food Ordering System. Vendors: SourceCodester.

Executive brief

SourceCodester Simple Online Food Ordering System is a web-based food ordering platform. A SQL injection vulnerability in the category management function allows attackers to manipulate database queries remotely without authentication, potentially exposing or modifying sensitive business data, customer information, and order details.

Technical details

The vulnerability is a SQL injection flaw in the /admin/ajax.php?action=delete_category endpoint, where the 'id' parameter is directly concatenated into SQL queries without sanitization or parameterized statements. An unauthenticated attacker can send a POST request with a malicious 'id' parameter containing SQL metacharacters (supporting time-based blind and boolean-based blind injection techniques) to read arbitrary database content, modify data, or execute administrative operations. The vulnerable component accepts user input directly from the HTTP POST body and passes it unsanitized to backend SQL execution. Patches should implement prepared statements with parameter binding and strict input validation on all user-supplied parameters.

Affected products

  • SourceCodester Simple Online Food Ordering System 1.0

Timeline

  • 2026-07-05: disclosed
  • 2026-08-20: advisory

References

Related threats