Executive brief
SourceCodester Simple Online Food Ordering System is a web-based food ordering platform. A SQL injection vulnerability in the category management function allows attackers to manipulate database queries remotely without authentication, potentially exposing or modifying sensitive business data, customer information, and order details.
Technical details
The vulnerability is a SQL injection flaw in the /admin/ajax.php?action=delete_category endpoint, where the 'id' parameter is directly concatenated into SQL queries without sanitization or parameterized statements. An unauthenticated attacker can send a POST request with a malicious 'id' parameter containing SQL metacharacters (supporting time-based blind and boolean-based blind injection techniques) to read arbitrary database content, modify data, or execute administrative operations. The vulnerable component accepts user input directly from the HTTP POST body and passes it unsanitized to backend SQL execution. Patches should implement prepared statements with parameter binding and strict input validation on all user-supplied parameters.
Affected products
- SourceCodester Simple Online Food Ordering System 1.0
Timeline
- 2026-07-05: disclosed
- 2026-08-20: advisory