Executive brief
SourceCodester's Online Food Ordering System is a web application used to manage restaurant food orders. A SQL injection vulnerability in the order processing page allows remote attackers to manipulate database queries via a malicious ID parameter, potentially exposing or modifying customer orders, payment data, and restaurant information. Exploit code is publicly available.
Technical details
The vulnerability is a SQL injection flaw in the /web/order.php file, where the ID parameter is not properly sanitized before being used in database queries. An unauthenticated attacker can send a crafted request with malicious SQL syntax in the ID field to execute arbitrary SQL commands on the backend database. The attack is remotely accessible over the network and does not require authentication. Successful exploitation allows an attacker to read, modify, or delete data from the database, or potentially execute operating system commands depending on database privileges. Public exploit code is available.
Affected products
- SourceCodester katojkalemba Online Food Ordering System 1.0
Timeline
- 2026-09-15: disclosed
- other: Exploit code made publicly available