Junglewise Threat Intelligence

CVE-2026-78197: SourceCodester Simple Online Food Ordering System SQL injection in admin AJAX

CVE-2026-78197 · Severity: high · CVSS 7.3 · Published 2026-08-24

Technologies: SourceCodester Simple Online Food Ordering System. Vendors: SourceCodester.

Executive brief

SourceCodester's Simple Online Food Ordering System is a PHP/MySQL-based web application used for managing online food orders. The application contains a SQL injection vulnerability in its admin panel that allows attackers to manipulate database queries and gain unauthorized access to sensitive data, modify records, or disrupt service without requiring authentication. This could expose customer orders, payment information, and admin credentials, leading to data breaches and business interruption.

Technical details

A SQL injection vulnerability exists in /fos/admin/ajax.php?action=save_user where the 'username' parameter is passed directly into SQL queries without proper input validation or parameterization. The vulnerability is remotely exploitable via POST requests and requires no authentication or user interaction. An attacker can inject malicious SQL payloads (time-based blind or boolean-based blind techniques) through the username field to extract database contents, modify data, or execute arbitrary database operations. Input validation and prepared statements with parameter binding should be implemented to remediate this issue.

Affected products

  • SourceCodester Simple Online Food Ordering System 1.0

Timeline

  • 2026-07-11: disclosed
  • 2026-08-24: advisory

References

Related threats