Junglewise Threat Intelligence

CVE-2026-79804: SililaWijesinghe Food Ordering System SQL injection in search

CVE-2026-79804 · Severity: high · CVSS 7.3 · Published 2026-08-25

Executive brief

SililaWijesinghe Food Ordering System is a web-based restaurant ordering platform. A SQL injection vulnerability in the search functionality allows unauthenticated attackers to manipulate database queries, leading to unauthorized access to sensitive data, database tampering, and potential complete system compromise without requiring login credentials.

Technical details

A SQL injection vulnerability exists in search.php where the POST parameter search_box is directly embedded into a PDO prepare() statement as LIKE '%{$search_box}%' without proper sanitization or parameterization. The vulnerable code treats user input as SQL commands rather than pure data, allowing attackers to inject SQL unions and other commands. No authentication is required to exploit this vulnerability—any remote attacker can submit a malicious search form to extract database contents, modify data, or gain system-level access. The vulnerability can be exploited via UNION-based SQL injection to enumerate database names and extract sensitive information. Patches are not currently available as the vendor did not respond to early disclosure.

Affected products

  • SililaWijesinghe Food Ordering System up to commit ba314e897e3365600461e5ea59432e39ceaa0fa5

Timeline

  • 2026-08-25: disclosed: Vulnerability published on NVD
  • 2026-07-01: other: Initial report submitted via GitHub issue

References