Executive brief
SourceCodester Simple Online Food Ordering System is a web-based food ordering application. A SQL injection vulnerability in the admin settings panel allows remote attackers to manipulate the database without authentication, potentially exposing customer data, orders, payment information, and enabling complete system compromise.
Technical details
A SQL injection vulnerability exists in /fos/admin/ajax.php?action=save_settings where the 'name' parameter is passed directly into SQL queries without sanitization or parameterized queries. The vulnerability is triggered via HTTP POST requests and requires no authentication. An attacker can inject arbitrary SQL code through the 'name' parameter to extract sensitive data, modify database records, delete data, or gain broader system control. The attack is remotely exploitable and publicly disclosed.
Affected products
- SourceCodester Simple Online Food Ordering System 1.0
Timeline
- 2026-07-11: disclosed
- 2026-08-24: advisory