PT-2025-30100 · Unknown · Food Ordering Review System
N0Name
·
Published
2025-07-18
·
Updated
2025-07-19
·
CVE-2025-7814
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
code-projects Food Ordering Review System version 1.0
Description
A critical vulnerability exists in the Food Ordering Review System. The vulnerability affects unknown code within the
/pages/signup function.php file. Manipulation of the fname argument can lead to SQL injection. The attack can be initiated remotely, and the exploit has been publicly disclosed. Other parameters may also be affected.Recommendations
Address the SQL injection vulnerability in the
/pages/signup function.php file by sanitizing the fname argument.Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Food Ordering Review System